GSA / GSA/ansible-https-proxy

Set Ownership on NGINX Directories and Files

Abierto
#3 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Sin datos de lenguaje
Estrellas
10
Forks
5
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

>Draft CIS Benchmark 1.1.4

## Description
The NGINX directories and files should be owned by `root `with the `root `(or root equivalent) group. This applies to all of the NGINX software directories and files installed. The only expected exception is that the NGINX web document root (`$NGINX\_PREFIX/html`) are likely to need a designated group to allow web content to be updated (such as webupdate) through a change management process.

## Rationale
Securing NGINX files and directories will reduce the probability of unauthorized modifications to those resources.

## Remediation
Perform the following: Set ownership on the $NGINX\_PREFIX directories such as `/usr/local/nginx: ` ``` # chown -R root:root $NGINX_PREFIX ```

## Audit
1. Identify files in the NGINX directory that are not owned by `root`: ``` # find $NGINX_PREFIX \! -user root -ls ```
2. Identify files in the NGINX directories other than html documents with a group other than `root`: ``` # find $NGINX_PREFIX -path $NGINX_PREFIX/html -prune -o \! -group root -ls ```

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.