Check: GEN008050
SUSE Linux Enterprise Server v11 for System z STIG:
GEN008050
(in versions v1 r12 through v1 r9)
Title
If the system is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords. (Cat II impact)
Discussion
The authentication of automated LDAP connections between systems must not use passwords since more secure methods are available, such as PKI and Kerberos. Additionally, the storage of unencrypted passwords on the system is not permitted.
Check Content
Check for the "bindpw" option being used in the "/etc/ldap.conf" file. # grep bindpw /etc/ldap.conf If an uncommented "bindpw" option is returned then a cleartext password is in the file, this is a finding.
Fix Text
Edit the "/etc/ldap.conf" file to use anonymous binding by removing the "bindpw" option.
Additional Identifiers
Rule ID: SV-45865r1_rule
Vulnerability ID: V-24384
Group Title: GEN008050
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000196 |
The information system, for password-based authentication, stores only cryptographically-protected passwords. |
Controls
Number | Title |
---|---|
IA-5 (1) |
Password-Based Authentication |