SV-270757r1184072_rule
V-270757
SRG-OS-000205-GPOS-00083
UBTU-24-700020
CAT II
10
Configure the system to set the appropriate permissions to the files and directories used by the systemd journal.
Create a drop-in file if it does not already exist with the following command:
$ sudo vi /etc/tmpfiles.d/zzz-systemd-stig.conf
Add or modify the following lines in the "/usr/lib/tmpfiles.d/zzz-systemd-stig.conf" file:
z /run/log/journal 0640 root systemd-journal - -
Z /run/log/journal/%m ~0640 root systemd-journal - -
z /var/log/journal 0640 root systemd-journal - -
z /var/log/journal/%m 0640 root systemd-journal - -
z /var/log/journal/%m/system.journal 0640 root systemd-journal - -
Note: Restart the system for these settings to take effect.
Verify the /run/log/journal and /var/log/journal directories have permissions set to "640" or less permissive with the following command:
$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %a" {} \;
/run/log/journal 640
/var/log/journal 640
/var/log/journal/6a52424faa6e480ea5fc7346b9345792 640
If any output returned has a permission set greater than 640, this is a finding.
Verify all files in the /run/log/journal and /var/log/journal directories have permissions set to "640" or less permissive with the following command:
$ sudo find /run/log/journal /var/log/journal -type f -exec stat -c "%n %a" {} \;
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system.journal 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000@0005f97cd4a8c9b5a.journal~ 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cd2a1e0a7-d58b848af46813a4.journal~ 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cb900e501-55ea053b7f75ae1c.journal~ 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000.journal 640
If any output returned has a permission set greater than "640", this is a finding.
V-270757
False
UBTU-24-700020
Verify the /run/log/journal and /var/log/journal directories have permissions set to "640" or less permissive with the following command:
$ sudo find /run/log/journal /var/log/journal -type d -exec stat -c "%n %a" {} \;
/run/log/journal 640
/var/log/journal 640
/var/log/journal/6a52424faa6e480ea5fc7346b9345792 640
If any output returned has a permission set greater than 640, this is a finding.
Verify all files in the /run/log/journal and /var/log/journal directories have permissions set to "640" or less permissive with the following command:
$ sudo find /run/log/journal /var/log/journal -type f -exec stat -c "%n %a" {} \;
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system.journal 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000@0005f97cd4a8c9b5a.journal~ 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cd2a1e0a7-d58b848af46813a4.journal~ 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/system@0005f97cb900e501-55ea053b7f75ae1c.journal~ 640
/var/log/journal/d5745ad455d34fb8b6f78be37c1fcd3e/user-1000.journal 640
If any output returned has a permission set greater than "640", this is a finding.
M
5673