SV-215170r508663_rule
V-215170
SRG-OS-000002-GPOS-00002
AIX7-00-001001
CAT II
10
From the command prompt, execute the following command to set the expiration time to 72 hours from now:
# chuser expires=1218103116 tmp_user
From the command prompt, execute the following command:
# lsuser -a expires tmp_user
The above command should yield the following output:
tmp_user expires=1218103116
From the command prompt, execute the following command:
# lsuser -a expires tmp_user
The above command should yield the following output:
tmp_user expires=0
Or
tmp_user expires=1215103116
The "expires" value is in "MMDDhhmmyy" form, or the value is "0".
If "expires" value is "0", or the expiration time is greater than "72" hours from the user creation time, this is a finding.
V-215170
False
AIX7-00-001001
From the command prompt, execute the following command:
# lsuser -a expires tmp_user
The above command should yield the following output:
tmp_user expires=0
Or
tmp_user expires=1215103116
The "expires" value is in "MMDDhhmmyy" form, or the value is "0".
If "expires" value is "0", or the expiration time is greater than "72" hours from the user creation time, this is a finding.
M
4012