OpenStack Compute - user/group ownership of config files set to root/nova - /etc/nova/rootwrap.conf

Information

Configuration files contain critical parameters and information required for smooth functioning of the component. If an unprivileged user, either intentionally or accidentally modifies or deletes any of the parameters or the file itself then it would cause severe availability issues causing a denial of service to the other end users. Thus user ownership of such critical configuration files must be set to root and group ownership must be set to nova.

Solution

User ownership of such critical configuration files must be set to root and group ownership must be set to nova.

See Also

http://docs.openstack.org/security-guide/compute/checklist.html

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Unix

Control ID: 3a604ef1b835213a6f53bffe6ab4b8b5c367e93757f33950d9a73b24d523c4c7