AIX7-00-003030 - AIX system must restrict the ability to switch to the root user to members of a defined group.

Information

Configuring a supplemental group for users permitted to switch to the root user prevents unauthorized users from accessing the root account, even with knowledge of the root credentials.

Solution

Use the 'chsec' command to only allow users in the adm group to su to root:

# chsec -f /etc/security/user -s root -a sugroups=adm

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215338r991589_rule, STIG-ID|AIX7-00-003030, STIG-Legacy|SV-101679, STIG-Legacy|V-91581, Vuln-ID|V-215338

Plugin: Unix

Control ID: 51b5075039a58673a9be2eba05daac89868d98d1331e264caf2aaa80eba70d99