Information
crontab is the program used to install, deinstall, or list the tables that drive the cron daemon. Each user can have their crontab, and though these are files in /var/cron/tabs, they are not intended to be edited directly.
If the /var/cron/allow file exists, you must be listed (one user per line) therein to be allowed to use this command. If the /var/cron/allow file does not exist but the /var/cron/deny file does exist, then you must not be listed in the /var/cron/deny file to use this command.
If both files exist, /var/cron/allow precedents. This means that /var/cron/deny is not considered when using the crontab.
If neither of these files exists, then depending on site-dependent configuration parameters, only the super user will be allowed to use this command, or all users will be able to use this command.
Regardless of the existence of any of these files, the root administrative user is always allowed to set up a crontab.
If the files /var/cron/allow and /var/cron/deny exist, they must be world-readable. If they are not, cron will only allow access to all users once the permissions are fixed.
Under the /var/cron/tabs directory, there is one file for each user's crontab. Users cannot edit the files under that directory directly to ensure that only users allowed by the system to run periodic tasks can add them, and only syntactically correct crontabs will be written there.
Note:
- Even though a given user is not listed in cron.allow, cron jobs can still be run as that user
- The files /var/cron/allow and /var/cron/deny, if they exist, only control administrative access to the crontab command for scheduling and modifying cron jobs
On many systems, only the system administrator is authorized to schedule cron jobs. Using the allow file to control who can run cron jobs enforces this policy. It is easier to manage an allow list than a deny list. In a deny list, you could potentially add a user ID to the system and forget to add it to the deny files.
Solution
-IF- cron is installed on the system:
Run the following commands to:
- Create /var/cron/allow if it doesn't exist
- Change owner or user root
- Change group owner to group wheel
- Change mode to 640 or more restrictive
# [ ! -e "/var/cron/allow" ] && touch /var/cron/allow
# chown root:wheel /var/cron/allow
# chmod u-x,g-wx,o-rwx /var/cron/allow
Run the following commands to:
-IF- /var/cron/deny exists:
- Change owner or user root
- Change group owner to group wheel
- Change mode to 640 or more restrictive
# [ -e "/var/cron/deny" ] && chown root:wheel /var/cron/deny
# [ -e "/var/cron/deny" ] && chmod u-x,g-wx,o-rwx /var/cron/deny