RHEL-07-020670 - The Red Hat Enterprise Linux operating system must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member.

Information

If a local interactive user's files are group-owned by a group of which the user is not a member, unintended users may be able to access them.

Solution

Change the group of a local interactive user's files and directories to a group that the interactive user is a member of. To change the group owner of a local interactive user's files and directories, use the following command:

Note: The example will be for the user smithj, who has a home directory of '/home/smithj' and is a member of the users group.

# chgrp users /home/smithj/<file>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_7_V3R15_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-204472r991589_rule, STIG-ID|RHEL-07-020670, STIG-Legacy|SV-86649, STIG-Legacy|V-72025, Vuln-ID|V-204472

Plugin: Unix

Control ID: 91d1bd115df18c9275bbd1c5c4da253dca895cafe6709f6f2951ec77dac4dd23