RHEL 9 /etc/gshadow- file must be owned by root.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-257904
RHEL-09-232120
SV-257904r991589_rule
Medium
Description
The "/etc/gshadow-" file is a backup of "/etc/gshadow", and as such, contains group password hashes. Protection of this file is critical for system security.
Details
Check Text (C-61645r925697_chk)
Verify the ownership of the "/etc/gshadow-" file with the following command:
$ sudo stat -c "%U %n" /etc/gshadow-
root /etc/gshadow-
If "/etc/gshadow-" file does not have an owner of "root", this is a finding.
Fix Text (F-61569r925698_fix)
Change the owner of the file /etc/gshadow- to root by running the following command:
$ sudo chown root /etc/gshadow-
A comprehensive tool for accessing, analyzing, and implementing
Defense Information Systems Agency (DISA) Security Technical
Implementation Guides (STIGs).
Featured Partners
Web page built by Cyber Protection Services. To learn more about our services, click here .
© 2025 DISA STIGS Viewer. All rights reserved.