Skip to content

6.1.3 Ensure permissions on /etc/group are configured

Audit#

Run the following command to verify /etc/group is mode 644 or more restrictive, Uid is 0/root and Gid is 0/root:

# stat -Lc "%n %a %u/%U %g/%G" /etc/group
/etc/group 644 0/root 0/root

Remediation#

Run the following commands to remove excess permissions, set owner, and set group on /etc/group:

# chmod u-x,go-wx /etc/group
# chown root:root /etc/group

Default Value:

/etc/group 644 0/root 0/root