SV-268122r1131049_rule
V-268122
SRG-OS-000063-GPOS-00032
ANIX-00-000680
CAT II
10
Update the NixOS config, typically stored either in /etc/nixos/configuration.nix or /etc/nixos/flake.nix, to only use the root user for files under /etc/audit.
Rebuild and switch to the new NixOS configuration:
$ sudo nixos-rebuild switch
Verify that the NixOS audit configuration files and directories are owned by root with the following command:
$ sudo find /etc/audit -exec stat -L -c "%U %n" {} \;
$ sudo find /etc/systemd/system -follow -iname "audit*service" -exec stat -c "%U %n" {} \;
root /etc/audit
root /etc/audit/auditd.conf
root /etc/systemd/system/audit.service
root /etc/systemd/system/auditd.service
root /etc/systemd/system/basic.target.wants/audit.service
root /etc/systemd/system/sysinit.target.wants/auditd.service
If the audit configuration files and directories are not owned by root, this is a finding.
V-268122
False
ANIX-00-000680
Verify that the NixOS audit configuration files and directories are owned by root with the following command:
$ sudo find /etc/audit -exec stat -L -c "%U %n" {} \;
$ sudo find /etc/systemd/system -follow -iname "audit*service" -exec stat -c "%U %n" {} \;
root /etc/audit
root /etc/audit/auditd.conf
root /etc/systemd/system/audit.service
root /etc/systemd/system/auditd.service
root /etc/systemd/system/basic.target.wants/audit.service
root /etc/systemd/system/sysinit.target.wants/auditd.service
If the audit configuration files and directories are not owned by root, this is a finding.
M
5658