GEN000000-HPUX0360 - The /etc/pam.conf file must be owned by root

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

/etc/pam.conf file is the system configuration file for the Pluggable Authentication Module (PAM) architecture. It supports per user authentication, account, session, and password management. If the configuration is modified maliciously, users may gain unauthorized system access.

Solution

If the system is operating in Trusted Mode, no fix is required.

For SMSE:
As root, change the file ownership.
# chown root /etc/pam.conf

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CCI|CCI-000366, CSCv6|3.1, Rule-ID|SV-52461r1_rule, STIG-ID|GEN000000-HPUX0360, Vuln-ID|V-40473

Plugin: Unix

Control ID: 2022af14b9af74119603b87b110cd12cec89413d06bfc63cda8d041d625b7ca5