GEN004510 - The SMTP service log file must not have an extended ACL.

Information

If the SMTP service log file has an extended ACL, unauthorized users may be allowed to access or to modify the log file.

Solution

This fix is applicable to both Postfix and sendmail servers.

Remove the extended ACL from the file.

# setfacl --remove-all <log file>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6, 800-53|SC-4, CAT|II, CCI|CCI-000225, CCI|CCI-001090, Rule-ID|SV-218543r603259_rule, STIG-ID|GEN004510, STIG-Legacy|SV-63755, STIG-Legacy|V-22442, Vuln-ID|V-218543

Plugin: Unix

Control ID: b52c77c44e34145518d8c061577cd7fd4bb1ed1dcd72f5e4f075510d803890f0