GEN008740 - The systems boot loader configuration file(s) must not have extended ACLs - s must not have extended ACLs.

Information

File system extended ACLs provide access to files beyond what is allowed by the mode numbers of the files. If extended ACLs are present on the system's boot loader configuration file(s), these files may be vulnerable to unauthorized access or modification, which could compromise the system's boot process.

Solution

Remove the extended ACL from the file.
# setfacl --remove-all /boot/grub/grub.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000225, Rule-ID|SV-63091r1_rule, STIG-ID|GEN008740, Vuln-ID|V-22585

Plugin: Unix

Control ID: b33839ec3449d3d9d0462b1133c064a034ca73d8449901355ecf1c46ac0b218c