Check: GEN000000-SOL00220
Solaris 9 X86 STIG:
GEN000000-SOL00220
(in version v1 r9)
Title
The /usr/aset/userlist file must exist. (Cat II impact)
Discussion
If the userlist file does not exist, then an unauthorized user may exist in the /etc/passwd file.
Check Content
Determine if ASET is being used. # crontab -l | grep aset If ASET is not used on the system, this is not applicable. If ASET is being used, but is not invoked with the "-u /usr/aset/userlist" option, this is a finding. Check the /usr/aset/userlist file. # ls -lL /usr/aset/userlist If /usr/aset/userlist file does not exist, this is a finding. An empty /usr/aset/userlist file, while not optimal, is not a finding.
Fix Text
Create the /usr/aset/userlist file and populate it with a list of authorized users.
Additional Identifiers
Rule ID: SV-955r2_rule
Vulnerability ID: V-955
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000032 |
Enforce information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows. |
CCI-000366 |
Implement the security configuration settings. |