GEN001475 - The /etc/group file must not contain any group password hashes.

Information

Group passwords are typically shared and should not be used. Additionally, if password hashes are readable by non-administrators, the passwords are subject to attack through lookup tables or cryptographic weaknesses in the hashes.

Solution

Edit /etc/group and change the password field to an exclamation point (!) to lock the group password.

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-22348, Rule-ID|SV-26447r1_rule, STIG-ID|GEN001475, Vuln-ID|V-22348

Plugin: Unix

Control ID: 2180a4f7a1bc56768c4b869eca0f7cfab89949c1da69498cb33ec28c3234379c