Check: GEN000980
AIX 6.1 SECURITY TECHNICAL IMPLEMENTATION GUIDE:
GEN000980
(in versions v1 r14 through v1 r10)
Title
The system must prevent the root account from directly logging in except from the system console. (Cat II impact)
Discussion
Limiting the root account direct logins to only system consoles protects the root account from direct unauthorized access from a non-console device.
Check Content
Check the remote login ability of the root account. Procedure: # lsuser -a rlogin root If the rlogin value is not false, this is a finding.
Fix Text
The root account can be protected from non-console device logins by setting rlogin = false in the root: stanza of the /etc/security/user file. #chsec -f /etc/security/user -s root -a rlogin=false
Additional Identifiers
Rule ID: SV-38683r1_rule
Vulnerability ID: V-778
Group Title: GEN000980
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000770 |
The organization requires individuals to be authenticated with an individual authenticator when a group authenticator is employed. |
Controls
Number | Title |
---|---|
IA-2 (5) |
Group Authentication |