GEN005420 - The /etc/syslog.conf file must be group-owned by bin, sys, or system.

Information

If the group owner of /etc/syslog.conf is not root, bin, or sys, unauthorized users could be permitted to view, edit, or delete important system messages handled by the syslog facility.

Solution

Change the group owner of the /etc/syslog.conf file to bin, sys, or system.
Procedure:
# chgrp system /etc/syslog.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-40364r1_rule, STIG-ID|GEN005420, Vuln-ID|V-4394

Plugin: Unix

Control ID: c6379e4fccd2d29c7e41edf8cbbcdde32fa030b6adaa7fdbd7999c7a1efe0ab5