GEN003210 M6 - The cron.deny file must not have an extended ACL - '/private/var/at/cron.deny'

Information

If there are excessive file permissions for the cron.deny file, sensitive information could be viewed or edited by unauthorized users.

Solution

Open a terminal session and enter the following command to remove the extended ACLs.

chmod -N /private/var/at/cron.deny

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-38115r1_rule, STIG-ID|GEN003210-M6, Vuln-ID|V-22389

Plugin: Unix

Control ID: 42cf7795746a76e6a47745bfb367d06d0be617589d3b6772e68e57a642919516