Major Hayden 35428ece12 V-3850{2,3,4}: Ownership/mode of /etc/shadow
Change-Id: Ic86060a4c37c430c61c7b27a08b22d0f9167784c
2015-10-09 10:31:01 -05:00

365 B

Although Ubuntu 14.04's default for /etc/shadow is 0640, the STIG requires a mode of 0000. This doesn't affect how the system operates since root is the only user that should be able to read from and write to /etc/shadow. Allowing users to read the file could open up the system to attacks since the password hashes can be dumped and brute forced.