AIX7-00-002127 - AIX system must require authentication upon booting into single-user and maintenance modes.

Information

This prevents attackers with physical access from trivially bypassing security on the machine and gaining root access. Such accesses are further prevented by configuring the bootloader password.

Solution

Assign the 'root' account a password using passwd command while logged on as 'root':
# passwd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215308r991589_rule, STIG-ID|AIX7-00-002127, STIG-Legacy|SV-101673, STIG-Legacy|V-91575, Vuln-ID|V-215308

Plugin: Unix

Control ID: 58359307c659598fd7534593399b4da78409bb955340f3433f6994dc1279c044