3.16 Verify that Docker socket file permissions are set to 660 or more restrictive

Information

https://docs.docker.com/reference/commandline/cli/#daemon-socket-option
2.https://docs.docker.com/articles/basics/#bind-docker-to-another-hostport-or-a-unix-socket

Solution

chmod 660 /var/run/docker.sock
This would set the file permissions of the Docker socket file to '660'.Impact-None.Default Value-By default, the permissions for Docker socket file is correctly set to '660'.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: becee14b38c70126dc4820b3115a6681e68480fe9a8e5654461573ddd0f26202