RHEL-10-400180 - RHEL 10 must enforce group ownership by "root" or a restricted logging group for audit log files to prevent unauthorized access.

Information

Unauthorized disclosure of audit records can reveal system and configuration data to attackers, thus compromising its confidentiality.

Satisfies: SRG-OS-000057-GPOS-00027, SRG-OS-000058-GPOS-00028, SRG-OS-000059-GPOS-00029, SRG-OS-000206-GPOS-00084

Solution

Configure RHEL 10 to enforce group ownership by "root" or a restricted logging group for audit log files to prevent unauthorized access.

Identify the group that is configured to own the audit log:

$ sudo grep -P '^[ ]*log_group[ ]+=.*$' /etc/audit/auditd.conf

Change the ownership to that group using the following command:

$ sudo chgrp ${log_group} ${log_file}

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_10_V1R1_STIG.zip