← All rules
SOCLE-CLD-FSP-066// File ownershipmediumfilesystem state

Verify Owner on cron.daily

Ensures the daily cron directory /etc/cron.daily is owned by the root user (UID 0).

Checked against a path’s metadata, mode, owner, group, SUID/SGID.

A pass proves✓ running now✓ on disk✓ survives rebootthe qualified verdict →
Debian 12CIS 1.1.0Debian 13CIS 1.0.0FedoraRHEL 10 / Rocky 10 / AlmaLinux 10RHEL 8 / Rocky 8 / AlmaLinux 8CIS 4.0.0RHEL 9 / Rocky 9 / AlmaLinux 9CIS 2.0.0Ubuntu 22.04CIS 3.0.0Ubuntu 24.04CIS 1.0.0Ubuntu 26.04
One check, maps to 3 standards

A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.

Why this rule matters

The /etc/cron.daily directory holds scripts that run automatically every day as root. If it is not owned by root, an unprivileged user could drop or modify a script there and have it executed with root privileges, a classic route to privilege escalation and persistence. Restricting ownership to root keeps scheduled execution trustworthy.

What Pavois checks

Pavois reads the effective owner of /etc/cron.daily via the InSpec file resource and asserts uid == 0, only when the directory exists (only_if). Inspecting the live inode ownership reflects the real on-disk state and catches drift introduced by package installs or manual changes, instead of an assumed default.

only_if { file('/etc/cron.daily').exist? }
describe file('/etc/cron.daily') do
  its('uid') { should eq 0 }
end

How to verify it is applied

Run stat -c '%U %u' /etc/cron.daily. Expected output: root 0. Alternatively ls -ld /etc/cron.daily should show root in the owner column.

Inspect & investigate

Ownership has no service log. Confirm the state with stat -c '%U %u' /etc/cron.daily. To trace changes, an auditd watch such as auditctl -w /etc/cron.daily -p wa -k cron-dir records writes/attribute changes in /var/log/audit/audit.log; cron execution itself is logged via journalctl -u cron (Debian/Ubuntu) or journalctl -u crond (RHEL family).

Remediation

No automated harden plan is defined for this rule, so it must be applied manually: run chown root /etc/cron.daily as root to set the owner to root.

Pavois applies this with its own harden engine, the plan below, not a shell script:

ownerroot
path/etc/cron.daily
resourcefile
pavois harden plan local

where the target is local, a user@host SSH alias, or a container , Docs

Impact & precautions

If misconfigured, a non-root user could plant a daily script that runs as root, leading to privilege escalation or persistence.

Precautions before applying: chown root /etc/cron.daily is safe and reversible with no service restart. Apply to the directory itself; if you use -R, review existing scripts first so you do not re-own files a packaging system expects to manage.

Standards mapping

StandardReferenceTypeVersionConfidence
CIS2.2.6, 2.4.1.4directper OS, see the benchmark tablehigh
NISTAC-6(1), CM-6(a)supporting800-53 Rev 5 · 800-171 Rev 2 (pinned)medium
PCI DSS2.2.6supporting4.0.1medium

Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.

Sources & references