Docker Enterprise daemon.json file ownership must be set to root:root.
An XCCDF Rule
Description
<VulnDiscussion>Verify that the daemon.json file ownership and group-ownership is correctly set to root. daemon.json file contains sensitive parameters that may alter the behavior of docker daemon. Hence, it should be owned and group-owned by root to maintain the integrity of the file. This file may not be present on the system. In that case, this recommendation is not applicable.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-235867r627728_rule
- Severity
- High
- References
- Updated
Remediation - Manual Procedure
If docker.daemon does not exist, create the file and set the ownership and group-ownership for the file to root.
Run the following command:
chown root:root /etc/docker/daemon.json