SV-215252r508663_rule
V-215252
SRG-OS-000337-GPOS-00129
AIX7-00-002032
CAT II
10
Create a role "auditadm" that is assigned with security related authorization with the following commend:
# mkrole authorizations="aix.security.audit,aix.security.user.audit,aix.security.role.audit" auditadm
Verify that an audit admin role has been configured to include the authorizations for auditing, namely "aix.security.audit,aix.security.user.audit,aix.security.role.audit":
# lsrole ALL |grep "aix.security.audit" |grep "aix.security.user.audit" |grep "aix.security.role.audit"
auditadm authorizations=aix.security.audit,aix.security.user.audit,aix.security.role.audit rolelist= groups= visibility=1 screens=* dfltmsg=Audit Administrator msgcat=role_desc.cat msgnum=15 msgset=1 auth_mode=INVOKER id=16
If the above command has no output, this is a finding.
V-215252
False
AIX7-00-002032
Verify that an audit admin role has been configured to include the authorizations for auditing, namely "aix.security.audit,aix.security.user.audit,aix.security.role.audit":
# lsrole ALL |grep "aix.security.audit" |grep "aix.security.user.audit" |grep "aix.security.role.audit"
auditadm authorizations=aix.security.audit,aix.security.user.audit,aix.security.role.audit rolelist= groups= visibility=1 screens=* dfltmsg=Audit Administrator msgcat=role_desc.cat msgnum=15 msgset=1 auth_mode=INVOKER id=16
If the above command has no output, this is a finding.
M
4012