AIX7-00-001000 - AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.


The '/etc/security/mkuser.sys.custom' is called by '/etc/security/mkuser.sys' to customize the new user account when a new user is created, or a user is logging into the system without a home directory. An improper '/etc/security/mkuser.sys.custom' script increases the risk that non-privileged users may obtain elevated privileges. It must not exist unless it is needed.


Remove the '/etc/security/mkuser.sys.custom' file using the following command:

# rm /etc/security/mkuser.sys.custom

See Also

Item Details

References: CAT|II, CCI|CCI-000015, Rule-ID|SV-215169r508663_rule, STIG-ID|AIX7-00-001000, STIG-Legacy|SV-101313, STIG-Legacy|V-91213, Vuln-ID|V-215169

Plugin: Unix

Control ID: d3fd7b8bd65a4bbad31f29a93e804301a9c66e689121b04789e44590338dd4b2