OpenStack Horizon - user/group of config files set to root/horizon - /etc/openstack-dashboard/local_settings.py

Information

Configuration files contain critical parameters and information required for smooth functioning of the component. If an unprivileged user, either intentionally or accidentally modifies or deletes any of the parameters or the file itself then it would cause severe availability issues causing a denial of service to the other end users. Thus user ownership of such critical configuration files must be set to root and group ownership must be set to horizon.

Solution

Set user and group ownership of the config file is set to root and horizon respectively

See Also

http://docs.openstack.org/security-guide/dashboard/checklist.html

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Unix

Control ID: ada5cb74ffbd1594a5519ab5a9a1e9019201222af3f488473a8ff6383843b255