Skip to content

AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.

An XCCDF Rule

Description

The "/etc/security/mkuser.sys.custom" is called by "/etc/security/mkuser.sys" to customize the new user account when a new user is created, or a user is logging into the system without a home directory. An improper "/etc/security/mkuser.sys.custom" script increases the risk that non-privileged users may obtain elevated privileges. It must not exist unless it is needed.

ID
SV-215169r958362_rule
Version
AIX7-00-001000
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Remove the "/etc/security/mkuser.sys.custom" file using the following command:

# rm /etc/security/mkuser.sys.custom