GEN000850 - The system must restrict the ability to switch to the root user to members of a defined group.

Information

Configuring a supplemental group for users permitted to switch to the root user prevents unauthorized users from accessing the root account, even with knowledge of the root credentials.

Solution

Use the chsec command to only allow users in the adm group to su to root.
#chsec -f /etc/security/user -s root -a sugroups=adm

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2c., CAT|III, CCI|CCI-000009, Group-ID|V-22308, Rule-ID|SV-38680r1_rule, STIG-ID|GEN000850, Vuln-ID|V-22308

Plugin: Unix

Control ID: 24fa444086738988dc288d9153b933357f93e8b424c4df9cb7afc56b37a10f83