5.1.1.3 Ensure syslogd default file permissions are configured

Information

syslogd will create log files that do not already exist on the system. This setting controls what permissions will be applied to these newly created files. These settings are handled by a different tool newsyslog which also handles the logfile rotation and retention.

It is important to ensure that log files have the correct permissions to ensure that sensitive data is archived and protected.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Edit either /etc/newsyslog.conf or a dedicated .conf file in /etc/newsyslog.conf.d/ and set the mode of the specific file to 644 or more restrictive.

Restart the service:

# service syslogd restart

Impact:

The system's global mask could be overridden to make the file permissions stricter than what is configured in newsyslog.conf with the mode directive.Thus, it is critical to ensure that the intended file creation mode is not overridden with less restrictive settings in /etc/newsyslog.conf, /etc/newsyslog.conf.d/*conf, /use/local/etc/newsyslog.conf.d/*conf files.

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|AU-2, 800-53|AU-7, 800-53|AU-12, 800-53|MP-2, CSCv7|5.1, CSCv7|6.2, CSCv7|6.3

Plugin: Unix

Control ID: d317349c17ae0090333beff0397514ab8108bedf5c08ed3ac52b5d9ecf18e9bd