4.7.2.13 /var/adm/cron/cron.allow

Information

The /var/adm/cron/cron.allow file contains a list of users who can schedule jobs via the cron command.

Rationale:

The /var/adm/cron/cron.allow file controls which users can schedule jobs via cron. Only the root user should have permissions to create, edit, or delete this file.

Solution

Apply the appropriate permissions to /var/adm/cron/cron.allow:

chown root:sys /var/adm/cron/cron.allow
chmod u=r,go= /var/adm/cron/cron.allow

Default Value:

N/A

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: bd9dd8a3263bfb298f53a977a54910526466f84ca4ca224ded98ce973c475b98