UCF STIG Viewer Logo

The /etc/passwd file must not contain password hashes.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22347 GEN001470 SV-38841r1_rule ECLP-1 Medium
Description
If password hashes are readable by non-administrators, the passwords are subject to attack through lookup tables or cryptographic weaknesses in the hashes.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-37834r1_chk )
AIX Does not store password hashes in the world read-able /etc/passwd file, so this check does not apply. Mark this as 'not a finding'.
Fix Text (F-33096r1_fix)
No fix, AIX is compliant.