Verify User Who Owns /etc/sysctl.d Directory
Ensures the /etc/sysctl.d directory is owned by root (uid 0).
Checked against a path’s metadata, mode, owner, group, SUID/SGID.
A mapping is a cross-reference to where each standard places this requirement, anchored and cross-validated, not a claim of equivalence. A passing check is evidence toward these references, how to read it.
Why this rule matters
The /etc/sysctl.d directory holds drop-in files that set kernel parameters at boot (network hardening, ASLR, kptr_restrict, etc.). If its owner is not root (uid 0), a non-privileged user could drop in a file that weakens these protections, for example re-enabling IP forwarding or disabling ASLR, undermining the system's kernel-level hardening at the next boot.
What Pavois checks
Pavois reads the effective owner uid of /etc/sysctl.d from the filesystem (stat), reporting the real on-disk state even after a package recreates the directory. The runtime kernel values are audited by the dedicated sysctl rules; this rule protects the source of those values from tampering.
only_if { file('/etc/sysctl.d').exist? }
describe file('/etc/sysctl.d') do
its('uid') { should eq 0 }
endHow to verify it is applied
Run stat -c '%U' /etc/sysctl.d. The expected output is root. Alternatively, ls -ld /etc/sysctl.d should show root in the owner column.
Inspect & investigate
Ownership changes are not logged by default; inspect with ls -ld /etc/sysctl.d. The kernel parameters these files set are visible at runtime with sysctl -a. If auditd watches /etc/sysctl.d, ownership changes appear in /var/log/audit/audit.log.
Remediation
No automated harden plan is defined for this rule, so it must be applied manually: chown root /etc/sysctl.d. Verify afterwards with stat -c '%U' /etc/sysctl.d.
Pavois applies this with its own harden engine, the plan below, not a shell script:
| owner | root |
|---|---|
| path | /etc/sysctl.d |
| resource | file |
pavois harden plan localwhere the target is local, a user@host SSH alias, or a container , Docs
Impact & precautions
Setting the owner to root is the expected state and has no functional impact; kernel parameters keep applying at boot via systemd-sysctl. There is no lockout or service-disruption risk. The change touches only directory metadata, not the parameter files' contents.
Standards mapping
| Standard | Reference | Type | Version | Confidence |
|---|---|---|---|---|
| ANSSI BP-028 | R50 | direct | 2.0 | high |
Each reference is a cross-reference anchored in the upstream benchmark and cross-validated against the SCAP Security Guide and ansible-lockdown, not a claim of equivalence. Direct = a prescriptive, line-level requirement; supporting = an abstract control family (NIST) the check provides evidence toward. How to read a mapping.