The OpenShift Audit Logs Directory Must Have Mode 0700
An XCCDF Rule
Description
To properly set the permissions of /var/log/openshift-apiserver/
, run the command:
$ sudo chmod 0700 /var/log/openshift-apiserver/
Rationale
If users can write to audit logs, audit trails can be modified or destroyed.
- ID
- xccdf_org.ssgproject.content_rule_directory_permissions_var_log_ocp_audit
- Severity
- Medium
- References
- Updated