AIX7-00-003203 - AIX must have the have the PowerSC Multi Factor Authentication Product configured.

Information

To assure accountability and prevent unauthenticated access, privileged and non-privileged users must utilize multifactor authentication to prevent potential misuse and compromise of the system.
Multifactor authentication uses two or more factors to achieve authentication.

Factors include:
1. Something you know (e.g., password/PIN);
2. Something you have (e.g., cryptographic identification device, token); and
3. Something you are (e.g., biometric).

The DoD CAC with DoD-approved PKI is an example of multifactor authentication.

Solution

Add or update the following lines in the '/etc/security/pmfa/pam_pmfa.conf' file:

TRUSTEDCAS = /<path_to_file>/server_ca.pem

Note: Verify with the SA/ISSO as to the location of the 'server_ca.pem' file.

MFA-URL = https://pmfa.example.com:6793/policyAuth/

SERVER-VERSION = 2

CTC-PROMPT-ONLY = Y

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215439r991589_rule, STIG-ID|AIX7-00-003203, STIG-Legacy|SV-103035, STIG-Legacy|V-92947, Vuln-ID|V-215439

Plugin: Unix

Control ID: 1fb23a093d5b498c69b971bc6a4a3c039c69dd112b9c19910c3d7f68a4a902ed