Skip to content

Verify Group Who Owns Backup gshadow File

An XCCDF Rule

Description

To properly set the group owner of /etc/gshadow-, run the command:

$ sudo chgrp root /etc/gshadow-

Rationale

The /etc/gshadow- file is a backup of /etc/gshadow, and as such, it contains group password hashes. Protection of this file is critical for system security.

ID
xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_gshadow
Severity
Medium
References
Updated



Remediation - Ansible

- name: Test for existence /etc/gshadow-
  stat:
    path: /etc/gshadow-
  register: file_exists
  tags:
  - DISA-STIG-RHEL-09-232125

Remediation - Shell Script

chgrp 0 /etc/gshadow-