By default, the xattrs
option is added to the FIPSR
ruleset in AIDE.
If using a custom ruleset or the xattrs
option is missing, add xattrs
to the appropriate ruleset.
For example, add xattrs
to the following line in /etc/aide.conf
:
FIPSR = p+i+n+u+g+s+m+c+acl+selinux+xattrs+sha256
AIDE rules can be configured in multiple ways; this is merely one example that is already
configured by default.
The remediation provided with this rule adds xattrs
to all rule sets available in
/etc/aide.conf