GEN000920 - The root account's home directory (other than /) must have mode 0700.

Information

Permissions greater than 0700 could allow unauthorized users access to the root home directory.

Solution

The root home directory will be configured to have permission set of 0700 or less permissive. Do not change the protections of the / directory. Use the following command to change protections for the root home directory:
# chmod 0700 /rootdir.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-775, Rule-ID|SV-37355r3_rule, STIG-ID|GEN000920, Vuln-ID|V-775

Plugin: Unix

Control ID: 160d9f021d69081d1cc8840d0287e06ac1cc8f1e95a37d282708703d25c02967