All system start-up files must be group-owned by root, sys, or bin.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216071SOL-11.1-020370SV-216071r959010_ruleCCI-000366medium
Description
If system start-up files do not have a group owner of root or a system group, the files may be modified by malicious users or intruders.
STIGDate
Solaris 11 X86 Security Technical Implementation Guide2025-05-05

Details

Check Text (C-216071r959010_chk)

Check run control scripts' group ownership. Procedure: # ls -lL /etc/rc* /etc/init.d If any run control script is not group-owned by root, sys, or bin, this is a finding.

Fix Text (F-17307r372596_fix)

Change the group ownership of the run control script(s) with incorrect group ownership. Procedure: # chgrp root <run control script>