GEN000440 - Successful and unsuccessful logins and logouts must be logged - 'unsuccessful logins are being logged'

Information

Monitoring and recording successful and unsuccessful logins assists in tracking unauthorized access to the system. Without this logging, the ability to track unauthorized activity to specific user accounts may be diminished.

Solution

Edit /etc/syslog.conf and add local log destinations for auth.* or both auth.notice and auth.info.

'auth.info /var/log/authlog'

Verify service startup scripts for syslog and utmp (if present) are enabled.

# vi /etc/rc.tcpip
Check the syslogd service is not commented out.

Refresh syslogd.
#refresh -s syslogd

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2d., CAT|II, CCI|CCI-000126, Group-ID|V-765, Rule-ID|SV-38935r1_rule, STIG-ID|GEN000440, Vuln-ID|V-765

Plugin: Unix

Control ID: 0bb2216bd6bb63752d202aadb819d43d3d090d3e044db9153bee9b00fb3e5186