GEN008340 - If using LDAP for auth or acct info, the LDAP TLS key must have mode 0600 or less permissive - '/etc/openldap/cacerts/key.pem'

Information

LDAP can be used to provide user authentication and account information, which are vital to system security. The LDAP client configuration must be protected from unauthorized modification. Note: Depending on the particular implementation, group and other read permission may be necessary for unprivileged users to successfully resolve account information using LDAP. This will still be a finding, as these permissions provide users with access to system authenticators.

Solution

Change the mode of the file.
# chmod 0600 <keypath>

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22573, Rule-ID|SV-37973r1_rule, STIG-ID|GEN008340, Vuln-ID|V-22573

Plugin: Unix

Control ID: b5f84aa4f50f45f682773d3d6ca0bf932eec6e40888bb753ec69054195b2689a