SOL-11.1-020080 - System packages must be configured with the vendor-provided files, permissions, and ownerships.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Failure to maintain system configurations may result in privilege escalation.

Solution

The Software Installation Profile is required.

Configure the package system to ensure that digital signatures are verified.

# pfexec pkg set-property signature-policy verify

Check that package permissions are configured per vendor requirements.

# pfexec pkg verify

If any errors are reported unrelated to STIG changes, use:

# pfexec pkg fix

to bring configuration settings and permissions into factory compliance.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_x86_V2R9_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001496, Rule-ID|SV-216050r603268_rule, STIG-ID|SOL-11.1-020080, STIG-Legacy|SV-60763, STIG-Legacy|V-47891, Vuln-ID|V-216050

Plugin: Unix

Control ID: 99a92715b43e95b39de6382522add037a4485d3059a2abc81a665c165e95c4e3