The /etc/zones directory, and its contents, must have the vendor default owner, group, and permissions.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216238SOL-11.1-100010SV-216238r959010_ruleCCI-000366low
Description
Incorrect ownership can result in unauthorized changes or theft of data.
STIGDate
Solaris 11 X86 Security Technical Implementation Guide2025-05-05

Details

Check Text (C-216238r959010_chk)

This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the ownership of the files and directories. # pkg verify system/zones The command should return no output. If output is produced, this is a finding.

Fix Text (F-17474r373091_fix)

This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The Software Installation profile is required. Change the ownership and permissions of the files and directories to the factory default. # pkg fix system/zones