Remediations on audit_control cause chaos if file is missing #166

Closed
opened 2026-01-19 18:29:28 +00:00 by michael · 1 comment
Owner

Originally created by @brodjieski on GitHub.

If /etc/security/audit_control is missing, the remediation script causes issues with the filesystem as it attempts to modify attributes on system folders.

Affects the following rules:
audit_acls_files_configure.yaml
audit_acls_folders_configure.yaml
audit_files_group_configure.yaml
audit_files_mode_configure.yaml
audit_files_owner_configure.yaml
audit_folder_group_configure.yaml
audit_folder_owner_configure.yaml
audit_folders_mode_configure.yaml

Originally created by @brodjieski on GitHub. If /etc/security/audit_control is missing, the remediation script causes issues with the filesystem as it attempts to modify attributes on system folders. Affects the following rules: audit_acls_files_configure.yaml audit_acls_folders_configure.yaml audit_files_group_configure.yaml audit_files_mode_configure.yaml audit_files_owner_configure.yaml audit_folder_group_configure.yaml audit_folder_owner_configure.yaml audit_folders_mode_configure.yaml
Author
Owner

@robertgendler commented on GitHub:

this was merged into main. closing the issue.

@robertgendler commented on GitHub: this was merged into main. closing the issue.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: usnistgov/macos_security#166