RHEL-10-400035 - RHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root".

Information

The "/etc/gshadow-" file is a backup of "/etc/gshadow", and as such contains group password hashes. Protection of this file is critical for system security.

Solution

Configure RHEL 10 so that the group of the "/etc/gshadow-" file is set to "root" by running the following command:

$ sudo chgrp root /etc/gshadow-

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_10_V1R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000213, Rule-ID|SV-281024r1165427_rule, STIG-ID|RHEL-10-400035, Vuln-ID|V-281024

Plugin: Unix

Control ID: a4bc18bbf89c00d59664183751ca5a51d3ffdbf5fa6683f21154b75a20fca705