The Photon operating system must be configured so the "/root" path is protected from unauthorized access.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256560PHTN-30-000091SV-256560r991589_ruleCCI-000366medium
Description
If the "/root" path is accessible to users other than root, unauthorized users could change the root partitions files.
STIGDate
VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide2024-12-16

Details

Check Text (C-256560r991589_chk)

At the command line, run the following command: # stat -c "%n permissions are %a and owned by %U:%G" /root Expected result: /root permissions are 700 and owned by root:root If the output does not match the expected result, this is a finding.

Fix Text (F-60178r887353_fix)

At the command line, run the following commands: # chmod 700 /root # chown root:root /root