STIGQter STIGQter: STIG Summary: Solaris 10 X86 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

Samba must be configured to not allow guest access to shares.

DISA Rule

SV-227936r603266_rule

Vulnerability Number

V-227936

Group Title

SRG-OS-000480

Rule Version

GEN006235

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the smb.conf file and change the guest ok setting to no.

Check Contents

Check the encryption setting for the Samba configuration. Default locations for this file include /etc, /etc/sfw, /etc/samba, and /etc/sfw/samba. If the system has Samba installed in non-standard locations, also check the smb.conf in those locations.

Procedure:
# grep -i 'guest ok' /etc/smb.conf /etc/sfw/smb.conf /etc/samba/smb.conf /etc/sfw/samba/smb.conf
If the setting exists and is set to yes, this is a finding.

Vulnerability Number

V-227936

Documentable

False

Rule Version

GEN006235

Severity Override Guidance

Check the encryption setting for the Samba configuration. Default locations for this file include /etc, /etc/sfw, /etc/samba, and /etc/sfw/samba. If the system has Samba installed in non-standard locations, also check the smb.conf in those locations.

Procedure:
# grep -i 'guest ok' /etc/smb.conf /etc/sfw/smb.conf /etc/samba/smb.conf /etc/sfw/samba/smb.conf
If the setting exists and is set to yes, this is a finding.

Check Content Reference

M

Target Key

4061

Comments