All accounts on AIX must be assigned unique User Identification Numbers (UIDs) and must authenticate organizational and non-organizational users (or processes acting on behalf of these users).
DISA Rule
SV-215176r508663_rule
Vulnerability Number
V-215176
Group Title
SRG-OS-000104-GPOS-00051
Rule Version
AIX7-00-001009
Severity
CAT I
CCI(s)
- CCI-000764 - The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).
- CCI-000804 - The information system uniquely identifies and authenticates non-organizational users (or processes acting on behalf of non-organizational users).
Weight
10
Fix Recommendation
Edit user accounts to provide unique names and UIDs for each account by editing the following files:
/etc/passwd
/etc/group
/etc/security/passwd
/etc/security/user
Check Contents
From the command prompt, run the following command to ensure there are no duplicate UIDs:
# usrck -n ALL
If any duplicate UIDs are found, this is a finding.
Vulnerability Number
V-215176
Documentable
False
Rule Version
AIX7-00-001009
Severity Override Guidance
From the command prompt, run the following command to ensure there are no duplicate UIDs:
# usrck -n ALL
If any duplicate UIDs are found, this is a finding.
Check Content Reference
M
Target Key
4012
Comments