RHEL-07-020700 - The Red Hat Enterprise Linux operating system must be configured so that all local initialization files for local interactive users are be group-owned by the users primary group or root.

Information

Local initialization files for interactive users are used to configure the user's shell environment upon logon. Malicious modification of these files could compromise accounts upon logon.

Solution

Change the group owner of a local interactive user's files to the group found in '/etc/passwd' for the user. To change the group owner of a local interactive user's home directory, use the following command:

Note: The example will be for the user smithj, who has a home directory of '/home/smithj' and has a primary group of users.

# chgrp users /home/smithj/.[^.]*

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R15_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-204475r991589_rule, STIG-ID|RHEL-07-020700, STIG-Legacy|SV-86655, STIG-Legacy|V-72031, Vuln-ID|V-204475

Plugin: Unix

Control ID: a0445aec2cd292a9d7b88c2fc715866e9b019b34c2f4af6a5dae4cfc686cd661