SV-215172r508663_rule
V-215172
SRG-OS-000027-GPOS-00008
AIX7-00-001004
CAT II
10
From the command prompt, execute the following command to set "maxulogs=10" for the "default:" stanza in the "/etc/security/user" file:
# chsec -f /etc/security/user -s default -a maxulogs=10
For each user account whose "maxulogs" value is greater than "10", or their "maxulogs" value is not set, or the values are set to "0", execute the following command to set "maxulogs=10":
# chuser maxulogs=10 [user_name]
From the command prompt, execute the following command to display maxulogs values for all the user account:
# lsuser -a maxulogs ALL
The above command should yield the following output:
root maxulogs=10
user_1 maxulogs=10
If the above command shows any user account that does not have the "maxulogs" attribute set, or its value is "0", or its value greater than "10", this is a finding.
V-215172
False
AIX7-00-001004
From the command prompt, execute the following command to display maxulogs values for all the user account:
# lsuser -a maxulogs ALL
The above command should yield the following output:
root maxulogs=10
user_1 maxulogs=10
If the above command shows any user account that does not have the "maxulogs" attribute set, or its value is "0", or its value greater than "10", this is a finding.
M
4012