SV-215208r508663_rule
V-215208
SRG-OS-000355-GPOS-00143
AIX7-00-001053
CAT II
10
Edit /etc/ntp.conf
Configure ntp server by adding the following line:
server server_ipaddr
Set maxpoll to <value> <=16 by adding the maxpoll <value>.
Restart the ntp daemon.
# stopsrc -s xntpd
# startsrc -s xntpd
Check if time synchronization application "ntpd" is running using the command:
# lssrc -s xntpd
Subsystem Group PID Status
xntpd tcpip 4784536 active
If "ntpd" is showing "inoperative", this is a finding.
Check that "ntp" server is configured using command:
# grep server /etc/ntp.conf
server 10.110.20.10
If the command returns no output, this is a finding.
Check the poll interval is less than 24 hours using command:
# grep maxpoll /etc/ntp.conf
maxpoll=16
If "maxpoll" is set to larger than "16" (2^16 seconds ~= 18hr), this is a finding.
V-215208
False
AIX7-00-001053
Check if time synchronization application "ntpd" is running using the command:
# lssrc -s xntpd
Subsystem Group PID Status
xntpd tcpip 4784536 active
If "ntpd" is showing "inoperative", this is a finding.
Check that "ntp" server is configured using command:
# grep server /etc/ntp.conf
server 10.110.20.10
If the command returns no output, this is a finding.
Check the poll interval is less than 24 hours using command:
# grep maxpoll /etc/ntp.conf
maxpoll=16
If "maxpoll" is set to larger than "16" (2^16 seconds ~= 18hr), this is a finding.
M
4012