ALMA-09-017840 - AlmaLinux OS 9 must define default permissions for logon and nonlogon shells.

Information

Setting the most restrictive default permissions ensures that when new accounts are created they do not have unnecessary access.

With a UMASK of 077, files will be created with 0600 permissions (owner read/write only) and directories will have 0700 permissions (owner read/write/execute only).

Solution

Configure AlmaLinux OS 9 to define default permissions for all authenticated users in such a way that the user can only read and modify their own files.

Change any found "umask" parameters in the "/etc/bashrc*", "/etc/csh*", and "/etc/profile*" files to "077":

umask 077

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-269237r1050119_rule, STIG-ID|ALMA-09-017840, Vuln-ID|V-269237

Plugin: Unix

Control ID: 99f1b59543fc6487b65697f6ffb1f3f58287d73336caafdf30cce01502cab0e8