GEN008740 - The system's boot loader configuration file(s) must not have extended ACLs.

Information

File system extended ACLs provide access to files beyond what is allowed by the mode numbers of the files. If extended ACLs are present on the system's boot loader configuration file(s), these files may be vulnerable to unauthorized access or modification, which could compromise the system's boot process.

Solution

If the file with the extended ACL resides on a UFS filesystem:
# getfacl /boot/grub/menu.lst

Remove each ACE from the file.
# setfacl -r [ACE] /boot/grub/menu.lst

If the file with the extended ACL resides on a ZFS filesystem:
# chmod A- /pool-name/boot/grub/menu.lst

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-000366, Rule-ID|SV-220127r510152_rule, STIG-ID|GEN008740, STIG-Legacy|SV-26985, STIG-Legacy|V-22585, Vuln-ID|V-220127

Plugin: Unix

Control ID: 4ede1dc46c1bd189cf850f75f4976914ce7789d9c8a91f9c24e044c21e693625