STIGUI
V-282674CAT II — Medium severitySV-282674r1201002_rule

The TOSS 5 /etc/shadow file must have mode 0000 to prevent unauthorized access.

Rule version TOSS-05-000191 · STIG v1 · 2026-08-20

Discussion

The "/etc/shadow" file contains the list of local system accounts and stores password hashes. Protecting this file is critical for system security. Failure to give ownership of this file to root provides the designated owner with access to sensitive information, which could weaken the system security posture.

Check

Verify the "/etc/shadow" file has mode "0000" using the following command:

$ sudo stat -c "%a %n" /etc/shadow

0 /etc/shadow

If a value of "0" is not returned, this is a finding.

Fix

Change the mode of the file "/etc/shadow" to "0000" using the following command:

$ sudo chmod 0000 /etc/shadow

Identifiers

Group ID
V-282674
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-282674r1201002_rule
Check ID
C-87235r1201000_chk
Fix ID
F-87140r1201001_fix