SV-260502r1184054_rule
V-260502
SRG-OS-000206-GPOS-00084
UBTU-22-232085
CAT II
10
Configure Ubuntu 22.04 LTS to set the appropriate group-ownership to the directories used by the systemd journal.
Create a drop-in file if it does not already exist with the following command:
$ sudo vi /etc/tmpfiles.d/zzz-systemd-stig.conf
Add or modify the following lines in the "/etc/tmpfiles.d/zzz-systemd-stig.conf" file:
z /run/log/journal 2750 root systemd-journal - -
z /var/log/journal 2750 root systemd-journal - -
z /var/log/journal/%m 2750 root systemd-journal - -
Restart the system for the changes to take effect.
Verify the /run/log/journal and /var/log/journal directories are group-owned by "systemd-journal" by using the following command:
$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %G" {} \;
/run/log/journal systemd-journal
/var/log/journal systemd-journal
/var/log/journal/3b018e681c904487b11671b9c1987cce systemd-journal
If any output returned is not group-owned by "systemd-journal", this is a finding.
V-260502
False
UBTU-22-232085
Verify the /run/log/journal and /var/log/journal directories are group-owned by "systemd-journal" by using the following command:
$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %G" {} \;
/run/log/journal systemd-journal
/var/log/journal systemd-journal
/var/log/journal/3b018e681c904487b11671b9c1987cce systemd-journal
If any output returned is not group-owned by "systemd-journal", this is a finding.
M
5594