GEN001374 - The /etc/nsswitch.conf file must not have an extended ACL.

Information

The nsswitch.conf file (or equivalent) configures the source of a variety of system security information including account, group, and host lookups. Malicious changes could prevent the system from functioning or compromise system security.

Solution

Remove the extended ACL from the file.
# setfacl --remove-all /etc/nsswitch.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22330, Rule-ID|SV-37334r1_rule, STIG-ID|GEN001374, Vuln-ID|V-22330

Plugin: Unix

Control ID: 588fd714d56e60b074fb8e2180f06ca71ce23288310bf9d61ec0fb8b7d2bebb2