SV-223775r1174002_rule
V-223775
SRG-OS-000355-GPOS-00143
RACF-OS-000190
CAT II
10
Whichever Time Protocol is used, consult the system programmer for configuration information. If using SNTP with the assistance of a systems programmer with UID(0) and/or SUPERUSER access, configure the Unix permission bits and user audit bits on the SNTPD to conform to the specifications below:
/usr/sbin/sntpd 1740 faf
Any Time Protocol must be configured to restrict access and/or control to appropriate personnel.
Configure SNTP as shown below:
From the ISPF Command Shell, enter:
cd /usr/sbin
ls -al
If the following file permission and user audit bits are true, this is not a finding.
/usr/sbin/sntpd 1740 faf
The following represents a hierarchy for permission bits from least restrictive to most restrictive:
7 rwx (least restrictive)
6 rw-
3 -wx
2 -w-
5 r-x
4 r--
1 --x
0 --- (most restrictive)
The possible audit bits settings are as follows:
f log for failed access attempts
a log for failed and successful access
- no auditing
V-223775
False
RACF-OS-000190
Any Time Protocol must be configured to restrict access and/or control to appropriate personnel.
Configure SNTP as shown below:
From the ISPF Command Shell, enter:
cd /usr/sbin
ls -al
If the following file permission and user audit bits are true, this is not a finding.
/usr/sbin/sntpd 1740 faf
The following represents a hierarchy for permission bits from least restrictive to most restrictive:
7 rwx (least restrictive)
6 rw-
3 -wx
2 -w-
5 r-x
4 r--
1 --x
0 --- (most restrictive)
The possible audit bits settings are as follows:
f log for failed access attempts
a log for failed and successful access
- no auditing
M
4101