4.1.1.10 Ensure access on /var/adm/cron/at.allow is configured

Information

The /var/adm/cron/at.allow file contains a list of users who can schedule jobs via the at command.

The /var/adm/cron/at.allow file controls which users can schedule jobs via the at command. Only the root user should have permissions to create, edit, or delete this file.

Solution

Apply the appropriate permissions to /var/adm/cron/at.allow :

chown root:sys /var/adm/cron/at.allow
chmod u=r,go= /var/adm/cron/at.allow

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, 800-53|AC-3(1), CSCv7|3.3, CSCv7|14.6

Plugin: Unix

Control ID: f1fbdca19e3229c70aea2b25dabae9ac328b7211bda315c5a95da3a95f81e070