STIGQter STIGQter: STIG Summary: Anduril NixOS Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Oct 2025:

NixOS audit configuration files must have a mode of 444 or less permissive.

DISA Rule

SV-268120r1131043_rule

Vulnerability Number

V-268120

Group Title

SRG-OS-000063-GPOS-00032

Rule Version

ANIX-00-000660

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure NixOS audit configuration and service files to have a mode of 444 or less permissive with the following command:

Rebuild and switch to the new NixOS configuration:
$ sudo nixos-rebuild switch

Check Contents

Verify that the NixOS audit configuration and service files have a mode of 444 or less permissive with the following commands:

$ sudo find -L /etc/audit -type f -exec stat -L -c "%a %n" {} \;
$ sudo find -L /etc/systemd/system -iname "audit*" -type f -exec stat -L -c "%a %n" {} \;
$ stat -c '%a %n' $(realpath /etc/systemd/system/audit*.service)

444 /etc/audit/auditd.conf
444 /etc/systemd/system/audit.service
444 /etc/systemd/system/auditd.service
444 /etc/systemd/system/basic.target.wants/audit.service
444 /etc/systemd/system/sysinit.target.wants/audit.service
444 /nix/store/dr3i90b3n1fb06fr1gw12jfg9wb8dkrc-unit-auditd.service/auditd.service
444 /nix/store/dc6s6z7ykbmq70i5z8cff0agwsmp9jhm-unit-audit.service/audit.service

If the audit configuration files have a mode more permissive than 444, this is a finding.

Vulnerability Number

V-268120

Documentable

False

Rule Version

ANIX-00-000660

Severity Override Guidance

Verify that the NixOS audit configuration and service files have a mode of 444 or less permissive with the following commands:

$ sudo find -L /etc/audit -type f -exec stat -L -c "%a %n" {} \;
$ sudo find -L /etc/systemd/system -iname "audit*" -type f -exec stat -L -c "%a %n" {} \;
$ stat -c '%a %n' $(realpath /etc/systemd/system/audit*.service)

444 /etc/audit/auditd.conf
444 /etc/systemd/system/audit.service
444 /etc/systemd/system/auditd.service
444 /etc/systemd/system/basic.target.wants/audit.service
444 /etc/systemd/system/sysinit.target.wants/audit.service
444 /nix/store/dr3i90b3n1fb06fr1gw12jfg9wb8dkrc-unit-auditd.service/auditd.service
444 /nix/store/dc6s6z7ykbmq70i5z8cff0agwsmp9jhm-unit-audit.service/audit.service

If the audit configuration files have a mode more permissive than 444, this is a finding.

Check Content Reference

M

Target Key

5658