UCF STIG Viewer Logo

The AIX root accounts home directory (other than /) must have mode 0700.


Overview

Finding ID Version Rule ID IA Controls Severity
V-215198 AIX7-00-001039 SV-215198r508663_rule Medium
Description
Users' home directories/folders may contain information of a sensitive nature. Non-privileged users should coordinate any sharing of information with an SA through shared resources.
STIG Date
IBM AIX 7.x Security Technical Implementation Guide 2022-06-06

Details

Check Text ( C-16396r294045_chk )
Check the mode of the root home directory by running the following commands:
# ls -ld `grep "^root" /etc/passwd | awk -F":" '{print $6}'`

The above command should yield the following output:
drwx------ 22 root system 4096 Sep 06 18:00 /root

If the mode of the directory is not equal to "0700", this is a finding.
Fix Text (F-16394r294046_fix)
Use the following command to change protections for the root home directory:
# chmod 0700 /root.