GEN004480 - The SMTP service log file must be owned by root.

Information

If the SMTP service log file is not owned by root, then unauthorized personnel may modify or delete the file to hide a system compromise.

Solution

Change the ownership of the Sendmail log file.
# chown root <sendmail log file>

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-837, Rule-ID|SV-837r2_rule, STIG-ID|GEN004480, Vuln-ID|V-837

Plugin: Unix

Control ID: 09565405c05117b9f5ee60095b7af0ea69e6b64ca93edaf39aa3636cad63971b