GEN004510 - The SMTP service log file must not have an extended ACL.

Information

If the SMTP service log file has an extended ACL, unauthorized users may be allowed to access or to modify the log file.

Solution

Remove the extended ACL from the SMTP service log file and disable extended permissions.
#acledit [ log file ]

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-38811r1_rule, STIG-ID|GEN004510, Vuln-ID|V-22442

Plugin: Unix

Control ID: 28bd5625698dcc0cfb16bbcc8de0c866521e9a951eacddcec48e1f481a51ee9a