Skip to content

Commit

Permalink
Merge pull request ComplianceAsCode#11639 from vojtapolasek/update_an…
Browse files Browse the repository at this point in the history
…ssi_r36

update notes of the R36 requirement for ANSSI
  • Loading branch information
marcusburghardt authored Mar 1, 2024
2 parents eb2f364 + ffceb64 commit d1c752a
Showing 1 changed file with 4 additions and 1 deletion.
5 changes: 4 additions & 1 deletion controls/anssi.yml
Original file line number Diff line number Diff line change
Expand Up @@ -862,7 +862,10 @@ controls:
and its group, and a full access to its owner. For services such as systemd, this value can
be defined directly in the configuration file of the service with the directive UMask=0027.
notes: >-
Currently there is no rule to check and remediate the UMask directive in systemd.
There are cases of Systemd services which would stop working in case umask
would be configured to 0027 for all services. One such example is the
Cups service which needs to create sockets which need to be available for
all users. Therefore, this part of the requirement can't be automated.
status: partial
rules:
- accounts_umask_etc_bashrc
Expand Down

0 comments on commit d1c752a

Please sign in to comment.