GEN004480 - The SMTP service log file must be owned by root.

Information

If the SMTP service log file is not owned by root, then unauthorized personnel may modify or delete the file to hide a system compromise.

Solution

Change the ownership of the sendmail log file.

Procedure:

The fix procedure is the same for both sendmail and Postfix.

# chown root <sendmail log file>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6, 800-53|SC-4, CAT|II, CCI|CCI-000225, CCI|CCI-001090, Rule-ID|SV-218541r603259_rule, STIG-ID|GEN004480, STIG-Legacy|SV-63751, STIG-Legacy|V-837, Vuln-ID|V-218541

Plugin: Unix

Control ID: 6f34885b1a685f2924e5025350835c253bfb0bda9e8277195f83fff5aec525bb