3.6.2.3 /var/spool/mqueue - permissions and ownership

Information

The recommended permissions and ownership for the /var/spool/mqueue directory are applied.

Rationale:

The sendmail daemon generally stores its queued mail in the /var/spool/mqueue directory. Queued messages are the messages that have not yet reached their final destination. To ensure the integrity of the messages during storage, the mail queue directory must be secured from unauthorized access.

NOTE: It is possible to specify an alternate spool directory in the /etc/mail/sendmail.cf file via the QueueDirectory parameter.

Solution

Set the recommended permissions and ownership on /var/spool/mqueue:

chmod u=rwx,go= /var/spool/mqueue
chown root /var/spool/mqueue

Default Value:

drwxrwx--- root system /var/spool/mqueue

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: cb56e98d5cae42fde2c7eb8e361168f820af6e697307786e60f875600213e385