6.6. Configure Audit_Control Owner to Mode 440 or Less Permissive Operation not permitted #235
-
I have been trying to work my way through these as a proof of concept but this one and a few after it that all ask to modify the /etc/security/audit_control all fail with Operation not permitted running as sudo Is this common or many due to another piece of security software we may have? |
Beta Was this translation helpful? Give feedback.
Replies: 5 comments 1 reply
-
And in that last sentence as my brain was working I think I answered my own question. Revered a VM back to default and tried it and no issue there. So it must be something else we are applying that locks that file down. |
Beta Was this translation helpful? Give feedback.
-
If you run |
Beta Was this translation helpful? Give feedback.
-
ok well now 6.14 returns ls -lO /etc/security/audit_control returns |
Beta Was this translation helpful? Give feedback.
-
This is what the script outputs on a freshly installed machine as well |
Beta Was this translation helpful? Give feedback.
-
It looks like your |
Beta Was this translation helpful? Give feedback.
It looks like your
/etc/security/audit_control
file has theuchg
flag set. This is likely due to installing cmdReporter or Jamf Compliance Reporter. With this flag set, you cannot modify the file, even withsudo
. You can runsudo chflags nouchg /etc/security/audit_control
to remove this flag, which will allow the compliance script to run without issue. We have plans to include this command in the script to account for this in future releases.