GEN004480 - The SMTP service log file must be owned by root.

Information

If the SMTP service log file is not owned by root, then unauthorized personnel may modify or delete the file to hide a system compromise.

Solution

Change the ownership of the sendmail log file.

Procedure:
The fix procedure is the same for both sendmail and Postfix.
# chown root <sendmail log file>

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-837, Rule-ID|SV-37496r1_rule, STIG-ID|GEN004430, Vuln-ID|V-22441

Plugin: Unix

Control ID: d1459a9eb2cce9cb11232032759330b1ad16aa6241d5655f26c05f3e7e924579