GEN000920 - The root account's home directory (other than /) must have mode 0700.

Information

Permissions greater than 0700 could allow unauthorized users access to the root home directory.

Solution

If the mode of the directory is not equal to 0700, this is a finding. If the home directory is /, this is not applicable. The root home directory will have permissions of 0700. Do not change the protections of the / directory. Use the following command to change protections for the root home directory.
# chmod 0700 /root.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-38941r1_rule, STIG-ID|GEN000920, Vuln-ID|V-775

Plugin: Unix

Control ID: 6193bb364502c65e59d99ef864a690cf21bc9b419810b8129f2704a5625bf331