Rule ID
SV-44758r1_rule
Version
V1R12
CCIs
The sysctl.conf file specifies the values for kernel parameters to be set on boot. These settings can affect the system's security.
Check the permissions of the file. # ls -lLd /etc/sysctl.conf If the permissions of the file or directory contains a '+', an extended ACL is present. If the file has an extended ACL and it has not been documented with the IAO, this is a finding.
Remove the extended ACL from the file. # setfacl --remove-all /etc/sysctl.conf