AIX system must require authentication upon booting into single-user and maintenance modes.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-215308AIX7-00-002127SV-215308r991589_ruleCCI-000366medium
Description
This prevents attackers with physical access from trivially bypassing security on the machine and gaining root access. Such accesses are further prevented by configuring the bootloader password.
STIGDate
IBM AIX 7.x Security Technical Implementation Guide2024-08-16

Details

Check Text (C-215308r991589_chk)

Verify that the "root" account has a password assigned: # cut -d: -f1,2 /etc/passwd | grep root root:! If the "root" account is not listed with an "!", this is a finding.

Fix Text (F-16504r294376_fix)

Assign the "root" account a password using passwd command while logged on as "root": # passwd