SV-215325r508663_rule
V-215325
SRG-OS-000259-GPOS-00100
AIX7-00-003009
CAT II
10
Remove the extended ACL(s) from the system command file(s) and set the extended permissions to disabled by running the following command:
# acledit [command-path ]/[ command-file]
Verify all system command files have no extended ACLs by running the following commands:
# aclget /etc
# aclget /bin
# aclget /usr/bin
# aclget /usr/lbin
# aclget /usr/ucb
# aclget /sbin
# aclget /usr/sbin
If any of the command files have extended permissions enabled, this is a finding.
V-215325
False
AIX7-00-003009
Verify all system command files have no extended ACLs by running the following commands:
# aclget /etc
# aclget /bin
# aclget /usr/bin
# aclget /usr/lbin
# aclget /usr/ucb
# aclget /sbin
# aclget /usr/sbin
If any of the command files have extended permissions enabled, this is a finding.
M
4012