UCF STIG Viewer Logo

The /etc/security/audit_user file must be owned by root.


Overview

Finding ID Version Rule ID IA Controls Severity
V-227534 GEN000000-SOL00060 SV-227534r603266_rule Medium
Description
The /etc/security/audit_user is a sensitive file and must be owned by root to prevent possible system compromise.
STIG Date
Solaris 10 X86 Security Technical Implementation Guide 2020-12-04

Details

Check Text ( C-29696r488129_chk )
Check /etc/security/audit_user ownership.

# ls -lL /etc/security/audit_user

If /etc/security/audit_user is not owned by root, this is a finding.
Fix Text (F-29684r488130_fix)
Change the owner of the /etc/security/audit_user file to root.
# chown root /etc/security/audit_user