GEN008120 M6 - The /etc/openldap/ldap.conf (or equivalent) file must not have an extended ACL - '/etc/openldap/ldap.conf'

Information

LDAP can be used to provide user authentication and account information, which are vital to system security. The LDAP client configuration must be protected from unauthorized modification.

Solution

Open a terminal session and enter the following command to remove the ACLs.

chmod -RN /etc/openldap/ldap.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-38157r1_rule, STIG-ID|GEN008120-M6, Vuln-ID|V-22562

Plugin: Unix

Control ID: 86d289bf0988ea27d2c9ccb99db24211ecfabb1e829c97634c9c841ea0dee6ae