GEN003430 - The 'at' directory must be group-owned by root, bin, or sys - at directory must be group-owned by root, bin, or sys.

Information

If the 'at' directory's group owner is not root, bin, or sys, unauthorized users could be allowed to view or edit files containing sensitive information within the directory.

Solution

Change the group ownership of the 'at' directory to root, bin, or sys.

Procedure:
# chgrp sys /var/spool/cron/atjobs

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-227774r603266_rule, STIG-ID|GEN003430, STIG-Legacy|SV-40414, STIG-Legacy|V-22396, Vuln-ID|V-227774

Plugin: Unix

Control ID: aafb44b3e0f8453ad9115d77ce45986a2b7f1319d0ab38bf003e96e18108f5fd