11.2 Samba: Set Secure Permissions on smb.conf File

Information

The smb.conf file is only to be writeable by root to prevent unauthorized changes of the configuration file

Solution

The default location for smb.conf is /usr/local/samba/lib. However, the file can be installed in other places by samba installation packages. If the configuration is not placed in the /usr/local/samba/lib directory, change the remediation and audit commands to reflect the correct location.
# chmod 644 /usr/local/samba/lib/smb.conf

See Also

https://workbench.cisecurity.org/files/614