Rule ID
SV-44757r1_rule
Version
V1R12
If the access permissions are more permissive than 0640, system security could be compromised.
Check the permissions of the file. # ls -lLd /etc/security/access.conf If the permissions of the file or directory contains a '+', an extended ACL is present. If the file has an extended ACL and it has not been documented with the IAO, this is a finding.
Remove the extended ACL from the file. # setfacl --remove-all /etc/security/access.conf