Skip to content

6.6. Configure Audit_Control Owner to Mode 440 or Less Permissive Operation not permitted #235

Answered by brodjieski
MatimusPrime asked this question in Q&A
Discussion options

You must be logged in to vote

It looks like your /etc/security/audit_control file has the uchg flag set. This is likely due to installing cmdReporter or Jamf Compliance Reporter. With this flag set, you cannot modify the file, even with sudo. You can run sudo chflags nouchg /etc/security/audit_control to remove this flag, which will allow the compliance script to run without issue. We have plans to include this command in the script to account for this in future releases.

Replies: 5 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@MatimusPrime
Comment options

Answer selected by MatimusPrime
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants