The AIX user home directories must not have extended ACLs.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-215332AIX7-00-003019SV-215332r991592_ruleCCI-000366medium
Description
Excessive permissions on home directories allow unauthorized access to user files.
STIGDate
IBM AIX 7.x Security Technical Implementation Guide2024-08-16

Details

Check Text (C-215332r991592_chk)

Verify user home directories have no extended ACLs using command: # cat /etc/passwd | cut -f 6,6 -d ":" | xargs -n1 aclget * * ACL_type AIXC * attributes: base permissions owner(root): rwx group(system): r-x others: r--- extended permissions disabled If extended permissions are not disabled, this is a finding.

Fix Text (F-16528r294448_fix)

Remove the extended ACL from the user home directory and disable extended permissions: # acledit <directory>