Check: AIX7-00-003132
IBM AIX 7.x STIG:
AIX7-00-003132
(in versions v2 r9 through v1 r1)
Title
The AIX DHCP client must not send dynamic DNS updates. (Cat II impact)
Discussion
Dynamic DNS updates transmit unencrypted information about a system including its name and address and should not be used unless needed.
Check Content
If AIX does not use DHCP client, this is Not Applicable. Determine if the system's DHCP client is configured to send dynamic DNS updates: # grep "^updateDNS" /etc/dhcpc.opt /etc/dhcpcd.ini If any lines are returned, this is a finding.
Fix Text
Configure the system's DHCP client to not send dynamic DNS updates. Remove or comment-out "updateDNS" lines from the "/etc/dhcpcd.ini" and "/etc/dhcpc.opt" files.
Additional Identifiers
Rule ID: SV-215427r508663_rule
Vulnerability ID: V-215427
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |