GEN008050 - If using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords.

Information

The authentication of automated LDAP connections between systems must not use passwords since more secure methods are available, such as PKI and Kerberos. Additionally, the storage of unencrypted passwords on the system is not permitted.

Solution

Edit the '/etc/ldap.conf' file to use anonymous binding by removing the 'bindpw' option.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|II, CCI|CCI-000196, Group-ID|V-24384, Rule-ID|SV-37643r3_rule, STIG-ID|GEN008050, Vuln-ID|V-24384

Plugin: Unix

Control ID: d223abcf32eb0d3151e3806f08c8167bf158aa8628a84f5809af556217fe195e