Common Controls Hub
The Photon operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
Setting the most restrictive default permissions ensures that when new accounts are created they do not have unnecessary access.
VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation Guide
Check Text ( C-62596r933627_chk )
At the command line, run the following command to verify the default umask configuration:
# grep '^UMASK' /etc/login.defs
If the "UMASK" option is not set to "077", is missing or commented out, this is a finding.
Fix Text (F-62505r933628_fix)
Navigate to and open:
Add or update the following line: