AIX7-00-003201 - The AIX operating system must be configured to authenticate using Multi Factor Authentication.

Information

To assure accountability and prevent unauthenticated access, privileged and non-privileged users must utilize multifactor authentication to prevent potential misuse and compromise of the system.
Multifactor authentication uses two or more factors to achieve authentication.

Factors include:
1. Something you know (e.g., password/PIN);
2. Something you have (e.g., cryptographic identification device, token); and
3. Something you are (e.g., biometric).

The DoD CAC with DoD-approved PKI is an example of multifactor authentication.

Solution

Run the following command to set the global and user stanza 'auth_type':

# chsec -f /etc/security/login.cfg -susw -a auth_type=PAM_AUTH

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215437r991589_rule, STIG-ID|AIX7-00-003201, STIG-Legacy|SV-103031, STIG-Legacy|V-92943, Vuln-ID|V-215437

Plugin: Unix

Control ID: 2c4b17086443d8f6ae0f566083cf809418dee01ff36fd1f378990d6f2844e283