OL 9 cron configuration directories must have a mode of 0700 or less permissive.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-271827 | OL09-00-002580 | SV-271827r1092193_rule | CCI-000366 | medium |
| Description | ||||
| Service configuration files enable or disable features of their respective services that if configured incorrectly can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the correct access rights to prevent unauthorized changes. | ||||
| STIG | Date | |||
| Oracle Linux 9 Security Technical Implementation Guide | 2025-05-08 | |||
Related Frameworks
4 paths across 3 frameworks
Related Frameworks
NIST 800-531 mapping
CM-6
1.00
- DISA · 1 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.4.1
1.00
- DISA · 1 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
- DISA · 1 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000366
1.00
- DISA · 1 · disa_xccdf · related
Details
Check Text (C-271827r1092193_chk)
Verify that OL 9 configures permissions of the cron directories with the following command:
$ find /etc/cron* -type d | xargs stat -c "%a %n"
700 /etc/cron.d
700 /etc/cron.daily
700 /etc/cron.hourly
700 /etc/cron.monthly
700 /etc/cron.weekly
If any cron configuration directory is more permissive than "700", this is a finding.
Fix Text (F-75784r1092192_fix)
Configure any OL 9 cron configuration directory with a mode more permissive than "0700" as follows:
$ sudo chmod 0700 [cron configuration directory]