Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-89879 | VRAU-SL-001535 | SV-100529r1_rule | Medium |
Description |
---|
Setting the most restrictive default permissions ensures that when new accounts are created they do not have unnecessary access. |
STIG | Date |
---|---|
VMware vRealize Automation 7.x SLES Security Technical Implementation Guide | 2018-10-12 |
Check Text ( C-89571r1_chk ) |
---|
Check for the configured "umask" value in "login.defs" with the following command: # grep UMASK /etc/login.defs If the default "umask" is not "077", this a finding. Note: If the default umask is "000" or allows for the creation of world-writable files this becomes a Severity Code I finding. |
Fix Text (F-96621r1_fix) |
---|
To configure the correct UMASK setting run the following command: # sed -i "/^[^#]*UMASK/ c\UMASK 077" /etc/login.defs |