Rule ID
SV-216342r959010_rule
Version
V3R5
CCIs
Setting a very secure default value for umask ensures that users make a conscious choice about their file permissions.
The package service/network/ftp must be installed for this check.
# pkg list service/network/ftp
If the output of this command is:
pkg list: no packages matching 'service/network/ftp' installed
no further action is required.
Determine if the FTP umask is set to 077.
# egrep -i "^UMASK" /etc/proftpd.conf | awk '{ print $2 }'
If 077 is not displayed, this is a finding.The root role is required. # pkg list service/network/ftp If the output of this command is: pkg list: no packages matching 'service/network/ftp' installed no further action is required. Otherwise, edit the FTP configuration file. # pfedit /etc/proftpd.conf Locate the line containing: Umask Change the line to read: Umask 077