Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-22451 | GEN005365 | SV-26733r1_rule | ECLP-1 | Medium |
Description |
---|
The snmpd.conf file contains authenticators and must be protected from unauthorized access and modification. If the file is not group-owned by a system group, it may be subject to access and modification from unauthorized users. |
STIG | Date |
---|---|
SOLARIS 10 SPARC SECURITY TECHNICAL IMPLEMENTATION GUIDE | 2017-01-05 |
Check Text ( C-27749r1_chk ) |
---|
Check the group ownership of the SNMP configuration files. Procedure: # ls -lL /etc/sma/snmp/snmpd.conf /var/sma_snmp/snmpd.conf /etc/snmp/conf/snmpd.conf /usr/sfw/lib/sma_snmp/snmpd.conf If the files are not group-owned by root, sys, or bin, this is a finding. |
Fix Text (F-23983r1_fix) |
---|
Change the group ownership of the SNMP configuration file. Procedure: # chgrp root /etc/sma/snmp/snmpd.conf /var/sma_snmp/snmpd.conf /etc/snmp/conf/snmpd.conf /usr/sfw/lib/sma_snmp/snmpd.conf |