GEN000440 - Successful and unsuccessful logins and logouts must be logged - 'successful logins are being logged'

Information

Monitoring and recording successful and unsuccessful logins assists in tracking unauthorized access to the system. Without this logging, the ability to track unauthorized activity to specific user accounts may be diminished.

Solution

Edit /etc/syslog.conf and add local log destinations for auth.* or both auth.notice and auth.info.

'auth.info /var/log/authlog'

Verify service startup scripts for syslog and utmp (if present) are enabled.

# vi /etc/rc.tcpip
Check the syslogd service is not commented out.

Refresh syslogd.
#refresh -s syslogd

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R13_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000126, Group-ID|V-765, Rule-ID|SV-38935r1_rule, STIG-ID|GEN000440

Plugin: Unix

Control ID: 0bb2216bd6bb63752d202aadb819d43d3d090d3e044db9153bee9b00fb3e5186