dev-sec / linux-baseline

DevSec Linux Baseline - InSpec Profile
https://dev-sec.io/baselines/linux/
Apache License 2.0
777 stars 186 forks source link

Add file system checks for other shadow and passwd/group files #161

Open cmhe opened 2 years ago

cmhe commented 2 years ago

Is your feature request related to a problem? Please describe. We currently have os-02 and os-03 which checks the permissions of /etc/shadow and /etc/passwd.

There are other files related to those, which are currently ignored:

Describe the solution you'd like Add checks for those files as well

chris-rock commented 2 years ago

Great idea @cmhe Happy to accept PRs to improve the controls