<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Non root / dtuser file with perm o+777 / o+rwx in OneAgent dir /var/lib/dynatrace/oneagent/agent/runtime in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Non-root-dtuser-file-with-perm-o-777-o-rwx-in-OneAgent-dir-var/m-p/196747#M22955</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;At some stage I got such a file on a OneAgent'ed Unix system AIX full-stack (though my sysadmins tell me it happened also on Linux infra-only system) with other+rwx Unix file permission :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;/var/lib/dynatrace/oneagent/agent/runtime/0x18eba097bca4a740_java_901179/dump/classes/original/com/ibm/mq/MQEnvironment.class,
Octal permissions: 0777, Text Permissions: -rwxrwxrwx-, owner: &amp;lt;AppUnixTechUser&amp;gt;, group: &amp;lt;AppUnixTechUserGroup&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;with &amp;lt;AppUnixTechUser&amp;gt; and&amp;lt;AppUnixTechUserGroup&amp;gt; *&lt;STRONG&gt;not*&lt;/STRONG&gt; being root:root (neither dtuser:dtuser, which btw does not exist on AIX system).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It makes unix file permission compliance health check raise incidents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is see this type of question is not really new. I can find in RFE and Questions, things relating to &lt;EM&gt;log&lt;/EM&gt; files though, not &lt;EM&gt;/var/lib/dynatrace&lt;/EM&gt; :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=""&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A class="" href="https://community.dynatrace.com/t5/Dynatrace-Open-Q-A/oneagent-file-permissions/m-p/54099/highlight/true#M2749" target="_blank" rel="noopener"&gt;Dynatrace Forum: oneagent file permissions&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=""&gt;&lt;A class="" href="https://community.dynatrace.com/t5/Dynatrace-product-ideas/world-writable-directories-and-logs/idi-p/151641" target="_blank" rel="noopener"&gt;Dynatrace RFE: Réalisée : world writable directories and logs &lt;/A&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;A class="" href="https://community.dynatrace.com/t5/Dynatrace-product-ideas/dtuser-file-access-permission-is-breaching-security-compliance/idi-p/191547" target="_blank" rel="noopener"&gt;Dynatrace RFE: dtuser file access permission is breaching security compliance requirement for RHEL8&lt;/A&gt; &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Is anyone facing this issue? &lt;/SPAN&gt;&lt;SPAN class=""&gt;Anything we can do? Removing o-wx permission would be nice.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;For the record: ticket: &lt;A href="https://one.dynatrace.com/hc/en-us/requests/83978" target="_blank" rel="noopener"&gt;https://one.dynatrace.com/hc/en-us/requests/83978&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2022 07:54:56 GMT</pubDate>
    <dc:creator>gilles_tabary</dc:creator>
    <dc:date>2022-10-20T07:54:56Z</dc:date>
    <item>
      <title>Non root / dtuser file with perm o+777 / o+rwx in OneAgent dir /var/lib/dynatrace/oneagent/agent/runtime</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Non-root-dtuser-file-with-perm-o-777-o-rwx-in-OneAgent-dir-var/m-p/196747#M22955</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;At some stage I got such a file on a OneAgent'ed Unix system AIX full-stack (though my sysadmins tell me it happened also on Linux infra-only system) with other+rwx Unix file permission :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;/var/lib/dynatrace/oneagent/agent/runtime/0x18eba097bca4a740_java_901179/dump/classes/original/com/ibm/mq/MQEnvironment.class,
Octal permissions: 0777, Text Permissions: -rwxrwxrwx-, owner: &amp;lt;AppUnixTechUser&amp;gt;, group: &amp;lt;AppUnixTechUserGroup&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;with &amp;lt;AppUnixTechUser&amp;gt; and&amp;lt;AppUnixTechUserGroup&amp;gt; *&lt;STRONG&gt;not*&lt;/STRONG&gt; being root:root (neither dtuser:dtuser, which btw does not exist on AIX system).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It makes unix file permission compliance health check raise incidents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is see this type of question is not really new. I can find in RFE and Questions, things relating to &lt;EM&gt;log&lt;/EM&gt; files though, not &lt;EM&gt;/var/lib/dynatrace&lt;/EM&gt; :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=""&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A class="" href="https://community.dynatrace.com/t5/Dynatrace-Open-Q-A/oneagent-file-permissions/m-p/54099/highlight/true#M2749" target="_blank" rel="noopener"&gt;Dynatrace Forum: oneagent file permissions&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=""&gt;&lt;A class="" href="https://community.dynatrace.com/t5/Dynatrace-product-ideas/world-writable-directories-and-logs/idi-p/151641" target="_blank" rel="noopener"&gt;Dynatrace RFE: Réalisée : world writable directories and logs &lt;/A&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;A class="" href="https://community.dynatrace.com/t5/Dynatrace-product-ideas/dtuser-file-access-permission-is-breaching-security-compliance/idi-p/191547" target="_blank" rel="noopener"&gt;Dynatrace RFE: dtuser file access permission is breaching security compliance requirement for RHEL8&lt;/A&gt; &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Is anyone facing this issue? &lt;/SPAN&gt;&lt;SPAN class=""&gt;Anything we can do? Removing o-wx permission would be nice.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;For the record: ticket: &lt;A href="https://one.dynatrace.com/hc/en-us/requests/83978" target="_blank" rel="noopener"&gt;https://one.dynatrace.com/hc/en-us/requests/83978&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 07:54:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Non-root-dtuser-file-with-perm-o-777-o-rwx-in-OneAgent-dir-var/m-p/196747#M22955</guid>
      <dc:creator>gilles_tabary</dc:creator>
      <dc:date>2022-10-20T07:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Non root / dtuser file with perm o+777 / o+rwx in OneAgent dir /var/lib/dynatrace/oneagent/agent/runtime</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Non-root-dtuser-file-with-perm-o-777-o-rwx-in-OneAgent-dir-var/m-p/196814#M22974</link>
      <description>&lt;P&gt;Hmmm... there... in the Manual :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="" href="https://www.dynatrace.com/support/help/shortlink/oneagent-security-linux#globally-writable-directories" target="_blank" rel="nofollow noopener"&gt;https://www.dynatrace.com/support/help/shortlink/oneagent-security-linux#globally-writable-directories&lt;/A&gt;&lt;BR /&gt;&lt;A class="" href="https://www.dynatrace.com/support/help/shortlink/oneagent-security-aix#globally-writable-directories" target="_blank" rel="nofollow noopener"&gt;https://www.dynatrace.com/support/help/shortlink/oneagent-security-aix#globally-writable-directories&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Globally writable directories&lt;BR /&gt;The OneAgent directory structure contains globally writable directories (1777 permissions). Changing these permissions by users is not supported."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorryyyy. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 11:24:05 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Non-root-dtuser-file-with-perm-o-777-o-rwx-in-OneAgent-dir-var/m-p/196814#M22974</guid>
      <dc:creator>gilles_tabary</dc:creator>
      <dc:date>2022-10-19T11:24:05Z</dc:date>
    </item>
  </channel>
</rss>

