The Photon operating system must be configured so that all system startup scripts are protected from unauthorized modification.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256562PHTN-30-000093SV-256562r991589_ruleCCI-000366medium
Description
If system startup scripts are accessible to unauthorized modification, this could compromise the system on startup.
STIGDate
VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide2024-12-16

Details

Check Text (C-256562r991589_chk)

At the command line, run the following command: # find /etc/rc.d/* -xdev -type f -a '(' -perm -002 -o -not -user root -o -not -group root ')' -exec ls -ld {} \; If any files are returned, this is a finding.

Fix Text (F-60180r887359_fix)

At the command line, run the following commands for each returned file: # chmod o-w <file> # chown root:root <file>