GEN001830 - All skeleton files (typically in /etc/skel) must be group-owned by root, bin, sys, system, or other.

Information

If the skeleton files are not protected, unauthorized personnel could change user startup parameters and possibly jeopardize user files.

Solution

Change the group-owner of the skeleton file to root, bin, sys, system, or other.

Procedure:
# chgrp <group> /etc/skel/[skeleton file]
or:
# ls -L /etc/skel|xargs stat -L -c %G:%n|egrep -v '^(root|bin|sy|sytem|other):'|cut -d: -f2|chgrp root
will change the group of all files not already one of the approved group to root.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22358, Rule-ID|SV-37237r1_rule, STIG-ID|GEN001830, Vuln-ID|V-22358

Plugin: Unix

Control ID: f915cc4e7fbf0c07c58d83b2eee363e625a9b1c4848446e13bf83611f55ffa53