AIX7-00-001134 - The password hashes stored on AIX system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm.

Information

Systems must employ cryptographic hashes for passwords using the SHA-2 family of algorithms or FIPS 140-2 approved successors. The use of unapproved algorithms may result in weak password hashes that are more vulnerable to compromise.

Solution

Set the system wide password algorithm to 'ssha256' or 'ssha512' by running the following command:

# chsec -f /etc/security/login.cfg -s usw -a pwd_algorithm=ssha512

Change the passwords for all accounts using non-compliant password hashes by running the following command:

$ passwd [user_name]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215230r991589_rule, STIG-ID|AIX7-00-001134, STIG-Legacy|SV-101671, STIG-Legacy|V-91573, Vuln-ID|V-215230

Plugin: Unix

Control ID: 159369c22ef36f80d0b2d984913d43020e8d1718004c7d37f9139ca387fd0dcc