AIX7-00-002061 - AIX must remove NOPASSWD tag from sudo config files.

Information

sudo command does not require reauthentication if NOPASSWD tag is specified in /etc/sudoers config file, or sudoers files in /etc/sudoers.d/ directory. With this tag in sudoers file, users are not required to reauthenticate for privilege escalation.

Solution

Edit '/etc/sudoers' using 'visudo' command to remove all the 'NOPASSWD' tags:
# visudo -f

Editing a sudo config file that is in '/etc/sudoers.d/' directory and contains the 'NOPASSWD' tags, use 'visudo' the command as follows:
# visudo -f /etc/sudoers.d/<config_file_name>

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V2R9_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-11, CAT|I, CCI|CCI-002038, Rule-ID|SV-215260r853468_rule, STIG-ID|AIX7-00-002061, STIG-Legacy|SV-101635, STIG-Legacy|V-91537, Vuln-ID|V-215260

Plugin: Unix

Control ID: 49245c296451f7f2c56e7fd256ad27549f56cfb2aa6d0c14ecb6eb64a3541ce2