GEN003080 - Crontab files must have mode 0600 or less, and files in cron script dirs must have mode 0700 or less - '/var/spool/cron/*'

Information

To protect the integrity of scheduled system jobs and prevent malicious modification to these jobs, crontab files must be secured.

Solution

Change the mode of the crontab files.
# chmod 0600 /var/spool/cron/* /etc/cron.d/* /etc/crontab

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-978, Rule-ID|SV-37466r1_rule, STIG-ID|GEN003080, Vuln-ID|V-978

Plugin: Unix

Control ID: 0649a23ef157da3e7e1ed4cbc49e390ed70152c75d9e6dca8bca2d39bee60ecf