SV-215214r508663_rule
V-215214
SRG-OS-000250-GPOS-00093
AIX7-00-001104
CAT II
10
Configure the LDAP client on AIX to use the SSL.
Edit /etc/security/ldap/ldap.cfg to have the following line:
useSSL:yes
Restart the client daemon:
# secldapclntd.
Run the following command to check if ldap_auth is used:
# grep -iE "^authtype:[[:blank:]]*ldap_auth" /etc/security/ldap/ldap.cfg
If the command has no output, this is Not Applicable.
Run the following command to check if SSL is used:
# grep -iE "^useSSL:[[:blank:]]*yes" /etc/security/ldap/ldap.cfg
useSSL:yes
If the command has no output, this is a finding.
V-215214
False
AIX7-00-001104
Run the following command to check if ldap_auth is used:
# grep -iE "^authtype:[[:blank:]]*ldap_auth" /etc/security/ldap/ldap.cfg
If the command has no output, this is Not Applicable.
Run the following command to check if SSL is used:
# grep -iE "^useSSL:[[:blank:]]*yes" /etc/security/ldap/ldap.cfg
useSSL:yes
If the command has no output, this is a finding.
M
4012