ALMA-09-017730 - AlmaLinux OS 9 must define default permissions for PAM users.

Information

Setting the most restrictive default permissions ensures that when new accounts are created they do not have unnecessary access.

With a UMASK of 077, files will be created with 0600 permissions (owner read/write only) and directories will have 0700 permissions (owner read/write/execute only).

Solution

Configure AlmaLinux OS 9 to define default permissions for all authenticated users so the user can only read and modify their own files.

Add or edit the following line at the top of /etc/pam.d/postlogin:

session optional pam_umask.so silent

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-269236r1050118_rule, STIG-ID|ALMA-09-017730, Vuln-ID|V-269236

Plugin: Unix

Control ID: cd30dffa869ca4cb3202b4cf4aab75f083eb09f0aa2bc8bbe3beb8a55381e8e3