OL6-00-000067 - The system boot loader configuration file(s) must have mode 0600 or less permissive.

Information

Proper permissions ensure that only the root user can modify important boot parameters.

Solution

File permissions for '/boot/grub/grub.conf' should be set to 600, which is the default. To properly set the permissions of '/boot/grub/grub.conf', run the command:

# chmod 600 /boot/grub/grub.conf

Boot partitions based on VFAT, NTFS, or other non-standard configurations may require alternative measures.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-208842r793627_rule, STIG-ID|OL6-00-000067, STIG-Legacy|SV-65149, STIG-Legacy|V-50943, Vuln-ID|V-208842

Plugin: Unix

Control ID: 9aa97e025dad548e5c136e6b03e63141178479772d7448c81102b85936b63061