SV-272484r1134875_rule
V-272484
SRG-OS-000445-GPOS-00199
RHEL-08-010455
CAT II
10
Configure the operating system to elevate the SELinux context when an administrator calls the sudo command.
Edit a file in the "/etc/sudoers.d" directory with the following command:
$ sudo visudo -f /etc/sudoers.d/<customfile>
Use the following example to build the <customfile> in the /etc/sudoers.d directory to allow any administrator belonging to a designated sudoers admin group to elevate their SELinux context with the use of the sudo command:
{designated_group_or_user_name} ALL=(ALL) TYPE=sysadm_t ROLE=sysadm_r ALL
Remove any configurations that conflict with the above from the following locations:
/etc/sudoers
/etc/sudoers.d/
Verify the operating system elevates the SELinux context when an administrator calls the sudo command with the following command:
This command must be run as root:
# grep -r sysadm_r /etc/sudoers /etc/sudoers.d
/etc/sudoers.d/admins:<username> ALL=(ALL) TYPE=sysadm_t ROLE=sysadm_r ALL
If conflicting results are returned, this is a finding.
If a designated sudoers administrator group or account(s) is not configured to elevate the SELinux type and role to "sysadm_t" and "sysadm_r" with the use of the sudo command, this is a finding.
V-272484
False
RHEL-08-010455
Verify the operating system elevates the SELinux context when an administrator calls the sudo command with the following command:
This command must be run as root:
# grep -r sysadm_r /etc/sudoers /etc/sudoers.d
/etc/sudoers.d/admins:<username> ALL=(ALL) TYPE=sysadm_t ROLE=sysadm_r ALL
If conflicting results are returned, this is a finding.
If a designated sudoers administrator group or account(s) is not configured to elevate the SELinux type and role to "sysadm_t" and "sysadm_r" with the use of the sudo command, this is a finding.
M
2921