File Locations - Host Based Authentication file

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

PostgreSQL configuration and data files should be protected against view and modification from unauthorized users.

Solution

Change owner and permissions of the PostgreSQL Host Based Authentication files. Example:

chown -R @PG_OWNER@:@PG_GROUP@ @PG_CONFIG_DIR@/pg_hba.conf
chmod -R u-x,g-rwx,o-rwx @PG_CONFIG_DIR@/pg_hba.conf

See Also

https://www.postgresql.org/docs/9.6/static/index.html

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: 5247648b1903a778a27617872888dd8175f764d4abf01fcb41717ba2b763eae6