GEN003410 - The 'at' directory must not have an extended ACL.

Information

If the 'at' directory has an extended ACL, unauthorized users could be allowed to view or to edit files containing sensitive information within the 'at' directory. Unauthorized modifications could result in Denial of Service to authorized 'at' jobs.

Solution

Remove the extended ACL from the directory.
# setfacl --remove-all /var/spool/at

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R17_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000225, Group-ID|V-22395, Rule-ID|SV-37523r1_rule, STIG-ID|GEN003410

Plugin: Unix

Control ID: 435eafba2bf5cb609bf0c448ad823bc1f09f6a618eff6953442dc6e7a3b995b5