GEN006330 - The /etc/news/passwd.nntp file must not have an extended ACL.

Information

Extended ACLs may provide excessive permissions on the /etc/news/passwd.nntp file, which may permit unauthorized access or modification to the NNTP configuration.

Solution

Remove the extended ACL from the file.
# setfacl --remove-all /etc/news/passwd.nntp

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22505, Rule-ID|SV-37733r1_rule, STIG-ID|GEN006330, Vuln-ID|V-22505

Plugin: Unix

Control ID: 8cce73550ded1cdf245544969b1635bb20519243748e34c92f7526b0708f24a3