SV-215208r508663_rule
V-215208
SRG-OS-000355-GPOS-00143
AIX7-00-001053
CAT II
10
Edit /etc/ntp.conf
Configure ntp server by adding the following line:
server server_ipaddr
Set maxpoll to <value>   <=16 by adding the maxpoll <value>.
Restart the ntp daemon.
# stopsrc -s xntpd
# startsrc -s xntpd
Check if time synchronization application "ntpd" is running using the command:
# lssrc -s xntpd
Subsystem         Group            PID                  Status 
 xntpd                   tcpip          4784536             active
If "ntpd" is showing "inoperative", this is a finding.
Check that "ntp" server is configured using command: 
# grep server /etc/ntp.conf
server 10.110.20.10
If the command returns no output, this is a finding.
Check the poll interval is less than 24 hours using command:
# grep maxpoll /etc/ntp.conf
maxpoll=16
If "maxpoll" is set to larger than "16" (2^16 seconds ~= 18hr), this is a finding.
V-215208
False
AIX7-00-001053
Check if time synchronization application "ntpd" is running using the command:
# lssrc -s xntpd
Subsystem         Group            PID                  Status 
 xntpd                   tcpip          4784536             active
If "ntpd" is showing "inoperative", this is a finding.
Check that "ntp" server is configured using command: 
# grep server /etc/ntp.conf
server 10.110.20.10
If the command returns no output, this is a finding.
Check the poll interval is less than 24 hours using command:
# grep maxpoll /etc/ntp.conf
maxpoll=16
If "maxpoll" is set to larger than "16" (2^16 seconds ~= 18hr), this is a finding.
M
4012