GEN006120 - The /usr/lib/smb.conf file must be group-owned by bin, sys, or system.

Information

If the group-owner of the smb.conf file is not root or a system group, the file may be maliciously modified and the Samba configuration could be compromised.

Solution

Change the group owner of the smb.conf file.
Procedure:
# chgrp system /usr/lib/smb.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-39231r1_rule, STIG-ID|GEN006120, Vuln-ID|V-1056

Plugin: Unix

Control ID: f844e09e1133f9467fa3645ba2ed90ff4f64d70c071d799d7bb7087f33349908