The AIX /etc/passwd, /etc/security/passwd, and/or /etc/group files must not contain a plus (+) without defining entries for NIS+ netgroups or LDAP netgroups.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-215206 | AIX7-00-001047 | SV-215206r991589_rule | CCI-000366 | medium |
| Description | ||||
| A plus (+) in system accounts files causes the system to lookup the specified entry using NIS. If the system is not using NIS, no such entries should exist. | ||||
| STIG | Date | |||
| IBM AIX 7.x Security Technical Implementation Guide | 2024-08-16 | |||
Details
Check Text (C-215206r991589_chk)
Check system configuration files for plus (+) entries using the following commands:
# cat /etc/passwd | grep -v "^#" | grep "\+"
# cat /etc/security/passwd | grep -v "^#" | grep "\+"
# cat /etc/group | grep -v "^#" | grep "\+"
If the "/etc/passwd", "/etc/security/passwd", and/or "/etc/group" files contain a plus (+) and do not define entries for NIS+ netgroups or LDAP netgroups, this is a finding.
Fix Text (F-16402r294070_fix)
Edit "/etc/passwd", "/etc/security/passwd", and/or "/etc/group" files and remove entries containing a plus (+).