GEN008050 - If the system is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - or equivalent must not contain passwords.

Information

The authentication of automated LDAP connections between systems must not use passwords since more secure methods are available, such as PKI and Kerberos. Additionally, the storage of unencrypted passwords on the system is not permitted.

Solution

Edit the '/etc/ldap.conf' file to use anonymous binding by removing the 'bindpw' option.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|II, CCI|CCI-000196, Rule-ID|SV-218695r603259_rule, STIG-ID|GEN008050, STIG-Legacy|SV-63355, STIG-Legacy|V-24384, Vuln-ID|V-218695

Plugin: Unix

Control ID: 783a3e6f941a60f53903c0f9efd6f7c13e1d1dcb731e69cd35eb0ac7accf22e6