SV-215205r508663_rule
V-215205
SRG-OS-000383-GPOS-00166
AIX7-00-001046
CAT II
10
Edit the "/etc/security/ldap/ldap.cfg" file to set the following two keywords to have value of "900":
usercachetimeout
groupcachetimeout
Restart LDAP client using command:
# /usr/sbin/restart-secldapclntd
If LDAP authentication is not required, this is Not Applicable.
Verify the "/etc/security/ldap/ldap.cfg" file to see if the following two keywords have a value that is greater than "900" seconds:
# grep -i usercachetimeout /etc/security/ldap/ldap.cfg
usercachetimeout: 900
# grep -i groupcachetimeout /etc/security/ldap/ldap.cfg
groupcachetimeout: 900
If any of the above keywords does not exist, is commented out, or any value of the above keywords are greater than "900", this is a finding.
V-215205
False
AIX7-00-001046
If LDAP authentication is not required, this is Not Applicable.
Verify the "/etc/security/ldap/ldap.cfg" file to see if the following two keywords have a value that is greater than "900" seconds:
# grep -i usercachetimeout /etc/security/ldap/ldap.cfg
usercachetimeout: 900
# grep -i groupcachetimeout /etc/security/ldap/ldap.cfg
groupcachetimeout: 900
If any of the above keywords does not exist, is commented out, or any value of the above keywords are greater than "900", this is a finding.
M
4012