16 - Restrict access to JETTY.policy - mode

Information

The JETTY.policy file is used to configure security policies for . It is recommended that access to this file has the proper permissions to properly protect from unauthorized changes.

Restricting access to this file will prevent local users from maliciously or inadvertently altering s security policy.

Solution

Perform the following to restrict access to $JETTY_HOME/..../JETTY.policy, set the owner and group owner of the contents of $JETTY_HOME/ to _admin and , respectively.
# chmod 770 $JETTY_HOME/..../JETTY.policy # chown _admin: $JETTY_HOME/...../JETTY.policy

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: f42c03381fea7510391b940f744fa50dd4fea53d42d642a2e8890fac30976056