STIGQter STIGQter: STIG Summary: Solaris 10 X86 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

The SNMP service must use only SNMPv3 or its successors.

DISA Rule

SV-227877r603266_rule

Vulnerability Number

V-227877

Group Title

SRG-OS-000095

Rule Version

GEN005305

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit non-compliant snmpd.conf files and remove references to the v1, v2c, community, or com2sec. Restart the SNMP service.
# svcadm restart svc:/application/management/sma:default

Check Contents

Verify the SNMP daemon is not configured to use the v1 or v2c security models.
# egrep '(v1|v2c|community|com2sec)' /etc/sma/snmp/snmpd.conf /var/sma_snmp/snmpd.conf /etc/snmp/conf/snmpd.conf /usr/sfw/lib/sma_snmp/snmpd.conf | grep -v '^#'
If any configuration is found, this is a finding.

Vulnerability Number

V-227877

Documentable

False

Rule Version

GEN005305

Severity Override Guidance

Verify the SNMP daemon is not configured to use the v1 or v2c security models.
# egrep '(v1|v2c|community|com2sec)' /etc/sma/snmp/snmpd.conf /var/sma_snmp/snmpd.conf /etc/snmp/conf/snmpd.conf /usr/sfw/lib/sma_snmp/snmpd.conf | grep -v '^#'
If any configuration is found, this is a finding.

Check Content Reference

M

Target Key

4061

Comments