AIX7-00-003138 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the AIX system.

Information

Trust files are convenient, but when used in conjunction with the remote login services, they can allow unauthenticated access to a system.

Solution

Remove the '.rhosts', '.shosts', 'hosts.equiv', and/or 'shosts.equiv' files.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215432r991591_rule, STIG-ID|AIX7-00-003138, STIG-Legacy|SV-101837, STIG-Legacy|V-91739, Vuln-ID|V-215432

Plugin: Unix

Control ID: 2f19adc5ff06111a84eb2d6331d9236b39f3b4672364092057f7544d210ff673