RHEL-10-400260 - RHEL 10 must enforce mode "0000" or less permissive for the "/etc/gshadow-" file to prevent unauthorized access.

Information

The "/etc/gshadow-" file is a backup of "/etc/gshadow", and as such contains group password hashes. Protection of this file is critical for system security.

Solution

Configure RHEL 10 so that the mode of the "/etc/gshadow-" file is set to "0000" by running the following command:

$ sudo chmod 0000 /etc/gshadow-

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_10_V1R1_STIG.zip