content
content copied to clipboard
6.2.12 Ensure users' .netrc Files are not group or world accessible (Scored)
Needs rule.
Or more ideally, someone could work with CIS to modernize their guidance.
Current content does not allow netrc files at all: system/accounts/accounts-restrictions/password_storage/no_netrc_files/rule.yml
The requirement 6.2.13 should be removed in favor of the 6.2.15. Ticket opened in CIS community: https://workbench.cisecurity.org/benchmarks/9090/tickets/16317 Also sent a change proposal for Fedora 28 vNext: https://workbench.cisecurity.org/benchmarks/9520/tickets/16318
The requirement is already removed in CIS RHEL9. It should also be removed from RHEL8.