SV-268120r1131043_rule
V-268120
SRG-OS-000063-GPOS-00032
ANIX-00-000660
CAT II
10
Configure NixOS audit configuration and service files to have a mode of 444 or less permissive with the following command:
Rebuild and switch to the new NixOS configuration:
$ sudo nixos-rebuild switch
Verify that the NixOS audit configuration and service files have a mode of 444 or less permissive with the following commands:
$ sudo find -L /etc/audit -type f -exec stat -L -c "%a %n" {} \;
$ sudo find -L /etc/systemd/system -iname "audit*" -type f -exec stat -L -c "%a %n" {} \;
$ stat -c '%a %n' $(realpath /etc/systemd/system/audit*.service)
444 /etc/audit/auditd.conf
444 /etc/systemd/system/audit.service
444 /etc/systemd/system/auditd.service
444 /etc/systemd/system/basic.target.wants/audit.service
444 /etc/systemd/system/sysinit.target.wants/audit.service
444 /nix/store/dr3i90b3n1fb06fr1gw12jfg9wb8dkrc-unit-auditd.service/auditd.service
444 /nix/store/dc6s6z7ykbmq70i5z8cff0agwsmp9jhm-unit-audit.service/audit.service
If the audit configuration files have a mode more permissive than 444, this is a finding.
V-268120
False
ANIX-00-000660
Verify that the NixOS audit configuration and service files have a mode of 444 or less permissive with the following commands:
$ sudo find -L /etc/audit -type f -exec stat -L -c "%a %n" {} \;
$ sudo find -L /etc/systemd/system -iname "audit*" -type f -exec stat -L -c "%a %n" {} \;
$ stat -c '%a %n' $(realpath /etc/systemd/system/audit*.service)
444 /etc/audit/auditd.conf
444 /etc/systemd/system/audit.service
444 /etc/systemd/system/auditd.service
444 /etc/systemd/system/basic.target.wants/audit.service
444 /etc/systemd/system/sysinit.target.wants/audit.service
444 /nix/store/dr3i90b3n1fb06fr1gw12jfg9wb8dkrc-unit-auditd.service/auditd.service
444 /nix/store/dc6s6z7ykbmq70i5z8cff0agwsmp9jhm-unit-audit.service/audit.service
If the audit configuration files have a mode more permissive than 444, this is a finding.
M
5658