GEN005040 - All FTP users must have a default umask of 077.

Information

The umask controls the default access mode assigned to newly created files. An umask of 077 limits new files to mode 700 or less permissive. Although umask is stored as a 4-digit number, the first digit representing special access modes is typically ignored or required to be zero (0).

Solution

Add the arguments -u077 to the ftpd on the /etc/inetd.conf and refresh inetd.
#vi /etc/inetd.conf
#refresh -s inetd
Change the umask of the ftp user.
#chuser umask=077 ftp

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-38813r1_rule, STIG-ID|GEN005040, Vuln-ID|V-12011

Plugin: Unix

Control ID: 49d95b84b4e71d88e68ee918c9dfc6909fd7ebd9c28b74b1488657061b058573