GEN000000-HPUX0110 - The HP-UX /etc/securetty file must not have an extended ACL

Information

File system extended ACLs provide access to files beyond what is allowed by the mode numbers of the files. Unauthorized modification of the /etc/securetty file could cause Denial of Service to authorized system consoles or add unauthorized system consoles.

Solution

Remove the optional ACL from the file.
# chacl -z /etc/securetty

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CCI|CCI-000225, CCI|CCI-000366, CSCv6|3.1, Rule-ID|SV-26994r1_rule, STIG-ID|GEN000000-HPUX0110, Vuln-ID|V-22591

Plugin: Unix

Control ID: 2fcf3d24edcfb184a1061a874f2b2cd8cc29c73d726b4945a87949bb06e048e8