STIGQter STIGQter: STIG Summary: Nutanix Acropolis GPOS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix OS must restrict the message log access permissions to reveal error messages only to authorized users.

DISA Rule

SV-279629r1192207_rule

Vulnerability Number

V-279629

Group Title

SRG-OS-000206-GPOS-00084

Rule Version

NXAC-OS-000207

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. AOS, Prism Central, and Files OS VMs are configured by default to have ownership and permission levels set correctly to meet this requirement. If these are found to be out of compliance, some corruption has taken place and the OS must be rebuilt.

2. For AHV, remove accounts that do not support approved system activities.

Check Contents

1. For AOS, Prism Central, and Files, verify the file permissions of /home/log/messages is greater than "600" and the ownership is "root" using the following command.

$ sudo stat -c "%a %n" /home/log/messages
600 /home/log/messages

$ sudo stat -c "%U" /home/log/messages
root

$ sudo stat -c "%G" /home/log/messages
root

2. For AHV, remove accounts that do not support approved system activities. List all interactive user accounts using the following command.

$ sudo awk -F: '$3 >= 1000 {print $1 " " $5}' /etc/passwd

If accounts exist on the system that are unauthorized or if the message log is not restricted as required, this is a finding.

Vulnerability Number

V-279629

Documentable

False

Rule Version

NXAC-OS-000207

Severity Override Guidance

1. For AOS, Prism Central, and Files, verify the file permissions of /home/log/messages is greater than "600" and the ownership is "root" using the following command.

$ sudo stat -c "%a %n" /home/log/messages
600 /home/log/messages

$ sudo stat -c "%U" /home/log/messages
root

$ sudo stat -c "%G" /home/log/messages
root

2. For AHV, remove accounts that do not support approved system activities. List all interactive user accounts using the following command.

$ sudo awk -F: '$3 >= 1000 {print $1 " " $5}' /etc/passwd

If accounts exist on the system that are unauthorized or if the message log is not restricted as required, this is a finding.

Check Content Reference

M

Target Key

5730