STIGQter STIGQter: STIG Summary: IBM AIX 7.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

AIX must provide xlock command in the CDE environment to let users retain their sessions lock until users are reauthenticated.

DISA Rule

SV-215188r508663_rule

Vulnerability Number

V-215188

Group Title

SRG-OS-000028-GPOS-00009

Rule Version

AIX7-00-001029

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install "X11.apps.clients" fileset from the AIX DVD Volume 1 using the following command (assuming that the DVD is mounted to/dev/cd0):

# installp -aXYgd /dev/cd0 -e /tmp/install.log X11.apps.clients

Check Contents

If AIX CDE (X11) is not used, this is Not Applicable.

Check the system to determine if "X11.apps.clients" is installed:
# lslpp -L X11.apps.clients

If the "X11.apps.clients" fileset is not installed, this is a finding.

Check if "xlock" command exists using the following command:
# ls /usr/bin/X11/xlock

The above command should display the following:
/usr/bin/X11/xlock

If the above command does not show that "/usr/bin/X11/xlock" exists, this is a finding.

Vulnerability Number

V-215188

Documentable

False

Rule Version

AIX7-00-001029

Severity Override Guidance

If AIX CDE (X11) is not used, this is Not Applicable.

Check the system to determine if "X11.apps.clients" is installed:
# lslpp -L X11.apps.clients

If the "X11.apps.clients" fileset is not installed, this is a finding.

Check if "xlock" command exists using the following command:
# ls /usr/bin/X11/xlock

The above command should display the following:
/usr/bin/X11/xlock

If the above command does not show that "/usr/bin/X11/xlock" exists, this is a finding.

Check Content Reference

M

Target Key

4012

Comments