Rule ID
SV-254197r991592_rule
Version
V1R2
CCIs
Excessive permissions on local interactive user home directories may allow unauthorized access to user files by other users.
Confirm Nutanix AOS has assigned home directory of all local interactive users has a mode of "0750" or less permissive.
Step 1. Determine interactive users
$ sudo cat $(awk -F: '($3>=1000)&&($7 !~ /nologin/){print $6}' /etc/passwd)
cat: /home/nutanix: Is a directory
cat: /home/admin: Is a directory
Step 2. Determine permissions on interactive users home directories.
$ sudo stat -c "%a %n" /home/admin
750 /home/admin
$ sudo stat -c "%a %n" /home/nutanix
750 /home/nutanix
If home directories referenced in "/etc/passwd" do not have a mode of "0750" or less permissive, this is a finding.Configure any interactive users home directory to have a mode of "0750" or less by running the command: $ sudo chmod 0750 [path to interactive users home directory]