UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The Oracle Linux operating system must be configured so that all files and directories contained in local interactive user home directories have a valid owner.


Overview

Finding ID Version Rule ID IA Controls Severity
V-221732 OL07-00-020660 SV-221732r744079_rule Medium
Description
Unowned files and directories may be unintentionally inherited if a user is assigned the same User Identifier "UID" as the UID of the un-owned files.
STIG Date
Oracle Linux 7 Security Technical Implementation Guide 2023-03-06

Details

Check Text ( C-23447r744077_chk )
Verify all files and directories in a local interactive user's home directory have a valid owner.

Check the owner of all files and directories in a local interactive user's home directory with the following command:

Note: The example will be for the user "smithj", who has a home directory of "/home/smithj".

$ sudo ls -lLR /home/smithj
-rw-r--r-- 1 smithj smithj 18 Mar 5 17:06 file1
-rw-r--r-- 1 smithj smithj 193 Mar 5 17:06 file2
-rw-r--r-- 1 smithj smithj 231 Mar 5 17:06 file3

If any files or directories are found without an owner, this is a finding.
Fix Text (F-23436r744078_fix)
Either remove all files and directories from the system that do not have a valid user, or assign a valid user to all unowned files and directories on OL 7 with the "chown" command:

Note: The example will be for the user smithj, who has a home directory of "/home/smithj".

$ sudo chown smithj /home/smithj/