UCF STIG Viewer Logo

For systems using NSS LDAP, the TLS certificate file must be owned by root.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22567 GEN008220 SV-38977r1_rule ECLP-1 Medium
Description
The NSS LDAP service provides user mappings which are a vital component of system security. Its configuration must be protected from unauthorized modification.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-37930r1_chk )
This check does not apply to AIX. The AIX LDAP SSL implementation uses IBM’s key management routines. The LDAP client configuration loads a key database including CA certificates and host certificates in a *.key database file. Individual files like the tls_cert, tls_cacert, tls_checkpeer, tls_crlcheck, and tls_key are not specified in the AIX LDAP client setup.
Fix Text (F-33186r1_fix)
No fix necessary.