Skip to content

IBM AIX 7.x Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • AIX system must restrict the ability to switch to the root user to members of a defined group.

    <VulnDiscussion>Configuring a supplemental group for users permitted to switch to the root user prevents unauthorized users from accessing th...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • All AIX Group Identifiers (GIDs) referenced in the /etc/passwd file must be defined in the /etc/group file.

    &lt;VulnDiscussion&gt;If a user is assigned the GID of a group not existing on the system, and a group with that GID is subsequently created, the u...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • All AIX files and directories must have a valid owner.

    &lt;VulnDiscussion&gt;Unowned files do not directly imply a security problem, but they are generally a sign that something is amiss. They may be ca...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The AIX hosts.lpd file must not contain a + character.

    &lt;VulnDiscussion&gt;Having the '+' character in the hosts.lpd (or equivalent) file allows all hosts to use local system print resources.&lt;/Vuln...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The chargen daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;This service is used to test the integrity of TCP/IP packets arriving at the destination. This chargen service is a characte...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The discard daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The discard service is used as a debugging and measurement tool. It sets up a listening socket and ignores data that it recei...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The dtspc daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The dtspc service deals with the CDE interface of the X11 daemon. It is started automatically by the inetd daemon in response...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The pcnfsd daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The pcnfsd service is an authentication and printing program, which uses NFS to provide file transfer services. This service ...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The rstatd daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The rstatd service is used to provide kernel statistics and other monitorable parameters pertinent to the system such as: CPU...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group
  • The rusersd daemon must be disabled on AIX.

    &lt;VulnDiscussion&gt;The rusersd service runs as root and provides a list of current users active on a system. An attacker may use this service to...
    Rule Medium Severity
  • SRG-OS-000095-GPOS-00049

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules