DISA STIG AIX 7.x v2r9

Audit Details

Name: DISA STIG AIX 7.x v2r9

Updated: 6/3/2024

Authority: DISA STIG

Plugin: Unix

Revision: 1.3

Estimated Item Count: 311

File Details

Filename: DISA_STIG_AIX_7.x_v2r9.audit

Size: 640 kB

MD5: 96bdfc9b978376926c15228e6d9f18db
SHA256: 61d26a2057710e251bf2605c887d5ba25a5b66813aa3dfd742eb556080ab965a

Audit Changelog

 
Revision 1.3

Jun 3, 2024

Functional Update
  • AIX7-00-001006 - If the AIX system is using LDAP for authentication or account information, the LDAP SSL, or TLS connection must require the server provide a certificate and this certificate must have a valid path to a trusted CA - Certificate Issuer
  • AIX7-00-001006 - If the AIX system is using LDAP for authentication or account information, the LDAP SSL, or TLS connection must require the server provide a certificate and this certificate must have a valid path to a trusted CA - ldapsslkeyf
  • AIX7-00-001006 - If the AIX system is using LDAP for authentication or account information, the LDAP SSL, or TLS connection must require the server provide a certificate and this certificate must have a valid path to a trusted CA - useSSL
  • AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - bindpwd DES
  • AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords - ldapsslkeypwd
  • AIX7-00-001046 - If LDAP authentication is required, AIX must setup LDAP client to refresh user and group caches less than a day - group cache
  • AIX7-00-001046 - If LDAP authentication is required, AIX must setup LDAP client to refresh user and group caches less than a day - user cache
  • AIX7-00-001105 - AIX must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions - Certificate Issuer
  • AIX7-00-001105 - AIX must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions - ldapsslkeyf
  • AIX7-00-001105 - AIX must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions - useSSL
Revision 1.2

Apr 29, 2024

Functional Update
  • AIX7-00-001015 - The shipped /etc/security/mkuser.sys file on AIX must not be customized directly.
Revision 1.1

Apr 15, 2024

Miscellaneous
  • Variables updated.