4.7.1.9 Ensure access to /etc/dt/config/Xconfig is configured

Information

The /etc/dt/config/Xconfig file is used to customize CDE DT login attributes. Ensure this file is owned by root:bin and permissions prevent group and other from writing to the file.

The /etc/dt/config/Xconfig file can be used to customize CDE DT login attributes. The default file, /usr/dt/config/Xconfig is unconditionally overwritten upon subsequent installation. It is recommended that the appropriate permissions and ownership are applied to secure the file.

Solution

Check to see if the /etc/dt/config/Xconfig exists:

ls -l /etc/dt/config/Xconfig

Apply the appropriate ownership and permissions to /etc/dt/config/Xconfig :

chown root:bin /etc/dt/config/Xconfig
chmod go-w /etc/dt/config/Xconfig

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 334f0816e0c06c50e5c33fa79f1a9c714ee5c40f37034fafe2afc7ff0796011d