UCF STIG Viewer Logo

If there are no X11 clients that require CDE on AIX, the dt service must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-91327 AIX7-00-003045 SV-101425r1_rule Medium
Description
This entry executes the CDE startup script which starts the AIX Common Desktop Environment. To prevent attacks this daemon should not be enabled unless there is no alternative.
STIG Date
IBM AIX 7.x Security Technical Implementation Guide 2020-02-24

Details

Check Text ( C-90481r1_chk )
From the command prompt, execute the following command:
# lsitab dt

If the command yields any output, this is a finding.
Fix Text (F-97525r1_fix)
In "/etc/inittab", remove the "dt" entry by running the following command:
# rmitab dt

To request the init command to re-examine the "/etc/inittab" file, enter:
# telinit q