OSX00012 - Verify file permissions

Information

This command will check a very large number of files on the system against what the package manager's database indicates they should be. This command will catch improperly loosened permissions.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Run the command- sudo diskutil repairPermissions / Note- If permissions were made more restrictive than the package manager expects (as later rules require), then these tightened permissions will need to be reapplied after running this command.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CSCv6|3.1, Rule-ID|SV-32237r1_rule, STIG-ID|OSX00012, Vuln-ID|V-25881

Plugin: Unix

Control ID: eb87249a24e338d55481b2542098edfd60ec953fe69cf48bacfa3979f0006397