4.1.1.11 Ensure access on /var/adm/cron/cron.allow is configured

Information

The /var/adm/cron/cron.allow file contains a list of users who can schedule jobs via the cron command.

The /var/adm/cron/cron.allow file controls which users can schedule jobs via cron Only the root user should have permissions to create, edit, or delete this file.

Solution

Apply the appropriate permissions to /var/adm/cron/cron.allow :

chown root:sys /var/adm/cron/cron.allow
chmod u=r,go= /var/adm/cron/cron.allow

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: f27b7c35a0429187a7091bb4258875eb02d6a71f60311ee373f42da1c7f55c1c