Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-215206 | AIX7-00-001047 | SV-215206r508663_rule | Medium |
Description |
---|
A plus (+) in system accounts files causes the system to lookup the specified entry using NIS. If the system is not using NIS, no such entries should exist. |
STIG | Date |
---|---|
IBM AIX 7.x Security Technical Implementation Guide | 2021-11-19 |
Check Text ( C-16404r294069_chk ) |
---|
Check system configuration files for plus (+) entries using the following commands: # cat /etc/passwd | grep -v "^#" | grep "\+" # cat /etc/security/passwd | grep -v "^#" | grep "\+" # cat /etc/group | grep -v "^#" | grep "\+" If the "/etc/passwd", "/etc/security/passwd", and/or "/etc/group" files contain a plus (+) and do not define entries for NIS+ netgroups or LDAP netgroups, this is a finding. |
Fix Text (F-16402r294070_fix) |
---|
Edit "/etc/passwd", "/etc/security/passwd", and/or "/etc/group" files and remove entries containing a plus (+). |