Rule ID
SV-45862r1_rule
Version
V1R12
CCIs
If the SMTP service log file has an extended ACL, unauthorized users may be allowed to access or to modify the log file.
# more /etc/rsyslog.conf Examine /etc/rsyslog.conf and determine the log file(s) receiving logs for "mail.crit", "mail.debug", mail.*, or "*.crit". Check the permissions on these log files. # ls -lL <log file> If the permissions include a '+', the file has an extended ACL. If the file has an extended ACL and it has not been documented with the IAO, this is a finding.
This fix is applicable to both Postfix and sendmail servers. Remove the extended ACL from the file. # setfacl --remove-all <log file>