{"description": "Change the group owner of interactive users files to the group found\nin <pre>/etc/passwd</pre> for the user. To change the group owner of a local\ninteractive user home directory, use the following command:\n<pre>$ sudo chgrp <i>USER_GROUP</i> /home/<i>USER</i>/.<i>INIT_FILE</i></pre>\n\nThis rule ensures every initialization file related to an interactive user\nis group-owned by an interactive user.", "rationale": "Local initialization files for interactive users are used to configure the\nuser's shell environment upon logon. Malicious modification of these files could\ncompromise accounts upon logon.", "severity": "medium", "references": {"srg": ["SRG-OS-000480-GPOS-00227"], "anssi": ["R50"], "cis": ["7.2.10"]}, "control_references": {"anssi": ["R50"], "cis": ["7.2.10"]}, "components": [], "identifiers": {}, "ocil_clause": "they are not", "ocil": "To verify the local initialization files of all local interactive users are group-\nowned by the appropriate user, inspect the primary group of the respective\nusers in <tt>/etc/passwd</tt> and verify all initialization files under the\nrespective users home directory. Check the group owner of all local interactive users\ninitialization files.", "oval_external_content": null, "fixtext": "", "checktext": "", "vuldiscussion": "", "srg_requirement": "", "warnings": [{"general": "Due to OVAL limitation, this rule can report a false negative in a\nspecific situation where two interactive users swap the group-ownership\nof their respective initialization files."}], "conflicts": [], "requires": [], "policy_specific_content": {}, "platform": "system_with_kernel", "platforms": ["system_with_kernel"], "sce_metadata": {}, "inherited_platforms": [], "cpe_platform_names": ["system_with_kernel"], "inherited_cpe_platform_names": [], "bash_conditional": null, "fixes": {}, "title": "User Initialization Files Must Be Group-Owned By The Primary Group", "definition_location": "/aptdata/openscap/scap-security-guide/linux_os/guide/system/accounts/accounts-session/accounts_user_dot_group_ownership/rule.yml", "template": null}