6.1.5 Ensure permissions on /etc/gshadow are configured - user and group

Information

The /etc/gshadow file is used to store the information about groups that is critical to the
security of those accounts, such as the hashed password and other security information.

Rationale:

If attackers can gain read access to the /etc/gshadow file, they can easily run a password
cracking program against the hashed password to break it. Other security information that
is stored in the /etc/gshadow file (such as group administrators) could also be useful to
subvert the group.

Solution

Run the one of the following chown commands as appropriate and the chmod to set
permissions on /etc/gshadow :

# chown root:root /etc/gshadow
# chown root:shadow /etc/gshadow
# chmod o-rwx,g-rw /etc/gshadow

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, 800-53|IA-5(1), CSCv6|16.14, CSCv7|16.4

Plugin: Unix

Control ID: 3f9872e89092860eb0561e1eeb53e8ba8b57124eeb1f440fad38a00d6ba62210