For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-cpg.md. A documentation index is available at /llms.txt.

Verify Permissions and Ownership of Old Passwords File

Description

To properly set the owner of /etc/security/opasswd, run the command:

$ sudo chown root /etc/security/opasswd 

To properly set the group owner of /etc/security/opasswd, run the command:

$ sudo chgrp root /etc/security/opasswd

To properly set the permissions of /etc/security/opasswd, run the command:

$ sudo chmod 0600 /etc/security/opasswd

Rationale

The /etc/security/opasswd file stores old passwords to prevent password reuse. Protection of this file is critical for system security.