STIGQter STIGQter: STIG Summary: IBM AIX 7.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

The .rhosts file must not be supported in AIX PAM.

DISA Rule

SV-215433r508663_rule

Vulnerability Number

V-215433

Group Title

SRG-OS-000480-GPOS-00229

Rule Version

AIX7-00-003139

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit "/etc/pam.conf" and remove the reference(s) to the "rhosts_auth" module.

Check Contents

Check the PAM configuration for "rhosts_auth" using command:
# grep rhosts_auth /etc/pam.conf |grep -v \#

If a "rhosts_auth" entry is found, this is a finding.

Vulnerability Number

V-215433

Documentable

False

Rule Version

AIX7-00-003139

Severity Override Guidance

Check the PAM configuration for "rhosts_auth" using command:
# grep rhosts_auth /etc/pam.conf |grep -v \#

If a "rhosts_auth" entry is found, this is a finding.

Check Content Reference

M

Target Key

4012

Comments