GEN000000-SOL00620 - The inherit-pkg-dir zone option must be set to none or the system default list defined for sparse root zones.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Solaris zones have the capability to inherit elements of the global zone's filesystem, which reduces the amount storage required for a zone, but also limits the flexibility of the zone. The inherit-pkg-dir option defines which paths are shared between the zones. If set incorrectly, private information from the global zone could be made available to the non-global zone. This option must be set to none (for a whole-root non-global zone), the vendor-specified list of paths for sparse-root non-global zones, or a list specified by the SA for operational reasons which has been justified and documented with the IAO.

Solution

Remove the inherit-pkg-dir lines or the directories not defined for sparse root zones.
# zonecfg -z <zone> remove inherit-pkg-dir=<somedir>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(4), CAT|II, CCI|CCI-000366, Rule-ID|SV-227553r505926_rule, STIG-ID|GEN000000-SOL00620, STIG-Legacy|SV-27022, STIG-Legacy|V-22607, Vuln-ID|V-227553

Plugin: Unix

Control ID: 191450f6c864e7ee62db10b54bc25dbf3cc8645d1ce0e82c5ab8b51d90a51492