SV-216120r603268_rule
V-216120
SRG-OS-000480
SOL-11.1-040390
CAT II
10
Note: This is the location for Solaris 11.1. For earlier versions, the information is in /etc/pam.conf.
The root role is required.
# ls -l /etc/pam.d
to identify the various configuration files used by PAM.
Search each file for the pam_rhosts_auth.so.1 entry.
# grep pam_rhosts_auth.so.1 [filename]
Identify the file with the line pam_hosts_auth.so.1 in it.
# pfedit [filename]
Insert a comment character (#) at the beginning of the line containing "pam_hosts_auth.so.1".
Note: This is the location for Solaris 11.1. For earlier versions, the information is in /etc/pam.conf.
Determine if host-based authentication services are enabled.
# grep 'pam_rhosts_auth.so.1' /etc/pam.conf /etc/pam.d/*| grep -vc '^#'
If the returned result is not 0 (zero), this is a finding.
V-216120
False
SOL-11.1-040390
Note: This is the location for Solaris 11.1. For earlier versions, the information is in /etc/pam.conf.
Determine if host-based authentication services are enabled.
# grep 'pam_rhosts_auth.so.1' /etc/pam.conf /etc/pam.d/*| grep -vc '^#'
If the returned result is not 0 (zero), this is a finding.
M
4021