GEN004500 - The SMTP service log file must have mode 0644 or less permissive.

Information

If the SMTP service log file is more permissive than 0644, unauthorized users may be allowed to change the log file.

Solution

Change the mode of the SMTP service log file.

Procedure:

The fix procedure is the same for both sendmail and Postfix.

# chmod 0644 <sendmail log file>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6, 800-53|SC-4, CAT|II, CCI|CCI-000225, CCI|CCI-001090, Rule-ID|SV-218542r603259_rule, STIG-ID|GEN004500, STIG-Legacy|SV-63753, STIG-Legacy|V-838, Vuln-ID|V-218542

Plugin: Unix

Control ID: a5a015072a48f16b5fb028efd07a168d980ddece706a61233874c1f590e3846c