GEN005420 - The /etc/syslog.conf file must be group-owned by root, bin, sys, or system.

Information

If the group owner of /etc/syslog.conf is not root, bin, or sys, unauthorized users could be permitted to view, edit, or delete important system messages handled by the syslog facility.

Solution

Procedure:
# chgrp root /etc/syslog.conf
Or
# chgrp root /etc/rsyslog.conf

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-4394, Rule-ID|SV-37711r2_rule, STIG-ID|GEN005420, Vuln-ID|V-4394

Plugin: Unix

Control ID: 18738041ab354e143f84c5e6fea0922732791400f84975ab6003f40c6222df8e