UCF STIG Viewer Logo

The /etc/syslog.conf file must be group-owned by wheel.


Overview

Finding ID Version Rule ID IA Controls Severity
V-4394 GEN005420 M6 SV-38051r1_rule ECLP-1 Medium
Description
If the group owner of /etc/syslog.conf is not root, bin, or sys, unauthorized users could be permitted to view, edit, or delete important system messages handled by the syslog facility.
STIG Date
MAC OSX 10.6 Workstation Security Technical Implementation Guide Draft 2013-01-10

Details

Check Text ( C-37600r1_chk )
Open a terminal session and enter the following command to verify the group ownership of the syslog.conf file.

ls -lL /etc/syslog.conf

If the syslog.conf file is not group owned by wheel, this is a finding.
Fix Text (F-32842r1_fix)
Open a terminal session and enter the following command to set the group ownership of the syslog.conf file.

chgrp wheel /etc/syslog.conf