SV-285222r1210426_rule
V-285222
SRG-OS-000480-GPOS-00228
PHTN-40-000267
CAT II
10
Navigate to and open:
/etc/sysctl.d/zz-stig-hardening.conf
Add or update the following line:
fs.suid_dumpable = 0
Note: "0" is recommended for normal operation. If core dumps need to be captured for troubleshooting purposes, then "2" is also an acceptable value.
At the command line, run the following command to load the new configuration:
# /sbin/sysctl --load /etc/sysctl.d/zz-stig-hardening.conf
Note: If the file zz-stig-hardening.conf does not exist, it must be created.
At the command line, run the following commands to verify the pam_deny.so module is used:
# grep '^auth' /etc/pam.d/system-auth
Example result:
auth required pam_faillock.so preauth
auth sufficient pam_unix.so
auth required pam_faillock.so authfail
auth optional pam_faildelay.so delay=4000000
auth required pam_deny.so
If the pam_deny.so module is not present, or is not configured as the last auth entry, this is a finding.
V-285222
False
PHTN-40-000267
At the command line, run the following commands to verify the pam_deny.so module is used:
# grep '^auth' /etc/pam.d/system-auth
Example result:
auth required pam_faillock.so preauth
auth sufficient pam_unix.so
auth required pam_faillock.so authfail
auth optional pam_faildelay.so delay=4000000
auth required pam_deny.so
If the pam_deny.so module is not present, or is not configured as the last auth entry, this is a finding.
M
5569