Skip to content

Docker Enterprise daemon.json file ownership must be set to root:root.

An XCCDF Rule

Description

Verify that the daemon.json file ownership and group-ownership is correctly set to root. daemon.json file contains sensitive parameters that may alter the behavior of docker daemon. Hence, it should be owned and group-owned by root to maintain the integrity of the file. This file may not be present on the system. In that case, this recommendation is not applicable.

ID
SV-235867r627728_rule
Version
DKER-EE-005330
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

If docker.daemon does not exist, create the file and set the ownership and group-ownership for the file to root.

Run the following command:
chown root:root /etc/docker/daemon.json