By default, the acl
option is added to the FIPSR
ruleset in AIDE.
If using a custom ruleset or the acl
option is missing, add acl
to the appropriate ruleset.
For example, add acl
to the following line in /etc/aide.conf
:
FIPSR = p+i+n+u+g+s+m+c+acl+selinux+xattrs+sha256
AIDE rules can be configured in multiple ways; this is merely one example that is already
configured by default.
The remediation provided with this rule adds acl
to all rule sets available in
/etc/aide.conf