UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The AIX root user home directory must not be the root directory (/).


Overview

Finding ID Version Rule ID IA Controls Severity
V-91751 AIX7-00-003140 SV-101849r1_rule Medium
Description
Changing the root home directory to something other than / and assigning it a 0700 protection makes it more difficult for intruders to manipulate the system by reading the files that root places in its default directory. It also gives root the same discretionary access control for root's home directory as for the other plain user home directories.
STIG Date
IBM AIX 7.x Security Technical Implementation Guide 2020-02-24

Details

Check Text ( C-90905r3_chk )
Determine if root is assigned a home directory other than "/" by listing its home directory by running command:

# grep "^root" /etc/passwd | awk -F":" '{print $6}'
/root

If the root user's home directory is "/", this is a finding.
Fix Text (F-97949r1_fix)
The root home directory should be something other than "/" (such as /root).

Run commands:
# mkdir /root
# chown root /root
# chgrp system /root
# chmod 700 /root

Then, edit the passwd file and change the root home directory to "/root".