GEN001390 M6 - The /etc/passwd file must not have an extended ACL

Information

File system ACLs can provide access to files beyond what is allowed by the mode numbers of the files. The /etc/passwd file contains the list of local system accounts. It is vital to system security and must be protected from unauthorized modification.

Solution

Open a terminal session and enter the following command to remove the extended ACLs.

chmod -N /etc/passwd

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-38089r1_rule, STIG-ID|GEN001390-M6, Vuln-ID|V-22334

Plugin: Unix

Control ID: cd234f324d1495be59aef36c9d96e7aed2e73b390f8ac2c82f3f4b15e94ed0e3