From 9853b6e6bfc6a60f3cf900fc7ac638c63fd70978 Mon Sep 17 00:00:00 2001 From: Peter Macko <44851174+macko1@users.noreply.github.com> Date: Mon, 14 Sep 2026 17:10:24 +0200 Subject: [PATCH] Add cyber.mil-provided SCAP Benchmark draft for RHEL 10 --- ...disa-stig-rhel10-V1R0-xccdf-scap-draft.xml | 20177 ++++++++++++++++ 1 file changed, 20177 insertions(+) create mode 100644 shared/references/disa-stig-rhel10-V1R0-xccdf-scap-draft.xml diff --git a/shared/references/disa-stig-rhel10-V1R0-xccdf-scap-draft.xml b/shared/references/disa-stig-rhel10-V1R0-xccdf-scap-draft.xml new file mode 100644 index 00000000000..e31a9e7518f --- /dev/null +++ b/shared/references/disa-stig-rhel10-V1R0-xccdf-scap-draft.xml @@ -0,0 +1,20177 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + Red Hat Enterprise Linux 10 + oval:mil.disa.stig.rhel10os:def:1 + + + + + + draft + Red Hat Enterprise Linux 10 STIG SCAP Benchmark + This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil. + + + + + DISA + STIG.DOD.MIL + + Benchmark Date: 09 Sep 2026 + 3.5.2 + 1.10.0 + + + Linux with BIND installed + + + + + + Gnome-shell Package + + + + + + Linux with Libreswan installed + + + + + + Linux with NFS mounts configured + + + + + + Linux UEFI system with boot partition file type other than VFAT + + + + + + Linux with postfix installed + + + + + + + 001.000.001 + + DISA + DISA + DISA + STIG.DOD.MIL + + + I - Mission Critical Classified + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + I - Mission Critical Public + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + I - Mission Critical Sensitive + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + II - Mission Support Classified + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + II - Mission Support Public + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + II - Mission Support Sensitive + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + III - Administrative Classified + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + III - Administrative Public + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + III - Administrative Sensitive + <ProfileDescription></ProfileDescription> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + CAT I Only + This profile only includes rules that are Severity Category I. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + SRG-OS-000324-GPOS-00125 + <GroupDescription></GroupDescription> + + RHEL-10-700970 + RHEL 10 must disable the debug-shell systemd service. + <VulnDiscussion>The debug-shell requires no authentication and provides root privileges to anyone who has physical access to the machine. While this feature is disabled by default, masking it adds an additional layer of assurance that it will not be enabled via a dependency in systemd. This also prevents attackers with physical access from trivially bypassing security on the machine through valid troubleshooting configurations and gaining root access when the system is rebooted.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002235 + Configure RHEL 10 to mask the debug-shell systemd service with the following command: + +$ sudo systemctl disable --now debug-shell.service +$ sudo systemctl mask --now debug-shell.service + + + + + + + + SRG-OS-000366-GPOS-00153 + <GroupDescription></GroupDescription> + + RHEL-10-001030 + RHEL 10 must check the GNU Privacy Guard (GPG) signature of software packages originating from external software repositories before installation. + <VulnDiscussion>Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and has been provided by a trusted vendor. + +All software packages must be signed with a cryptographic key recognized and approved by the organization. + +Verifying the authenticity of software prior to installation validates the integrity of the software package received from a vendor.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-003992 + Configure RHEL 10 dnf to always check the GPG signature of software packages originating from external software repositories before installation. + +Add or update the following line in the [main] section of the "/etc/dnf/dnf.conf" file: + +gpgcheck=1 + + + + + + + + SRG-OS-000366-GPOS-00153 + <GroupDescription></GroupDescription> + + RHEL-10-001040 + RHEL 10 must check the GNU Privacy Guard (GPG) signature of locally installed software packages before installation. + <VulnDiscussion>Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and that it has been provided by a trusted vendor. + +All software packages must be signed with a cryptographic key recognized and approved by the organization. + +Verifying the authenticity of software prior to installation validates the integrity of the software package received from a vendor.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-003992 + Configure RHEL 10 dnf to always check the GPG signature of local software packages before installation. + +Add or update the following line in the [main] section of the "/etc/dnf/dnf.conf" file: + +localpkg_gpgcheck=1 + + + + + + + + SRG-OS-000366-GPOS-00153 + <GroupDescription></GroupDescription> + + RHEL-10-001050 + RHEL 10 must have GNU Privacy Guard (GPG) signature verification enabled for all software repositories. + <VulnDiscussion>Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and has been provided by a trusted vendor. + +All software packages must be signed with a cryptographic key recognized and approved by the organization. + +Verifying the authenticity of software prior to installation validates the integrity of the software package received from a vendor.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-003992 + Configure RHEL 10 software repositories defined in "/etc/yum.repos.d/" to have "gpgcheck" enabled with the following command: + +$ sudo sed -i 's/gpgcheck\s*=.*/gpgcheck=1/g' /etc/yum.repos.d/* + + + + + + + + SRG-OS-000420-GPOS-00186 + <GroupDescription></GroupDescription> + + RHEL-10-000530 + RHEL 10 must use a separate file system for user home directories (such as "/home" or an equivalent). + <VulnDiscussion>Ensuring that "/home" is mounted on its own partition enables the setting of more restrictive mount options and helps ensure that users cannot trivially fill partitions used for log or audit data storage.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002385 + Configure RHEL 10 to use a separate file system for user home directories by migrating the "/home" directory onto a separate file system/partition. + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-200020 + RHEL 10 must not have the "telnet-server" package installed. + <VulnDiscussion>It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities are often overlooked and therefore, may remain unsecure. They increase the risk to the platform by providing additional attack vectors. + +The telnet service provides an unencrypted remote access service, which does not provide for the confidentiality and integrity of user passwords or the remote session. If a privileged user were to log in using this service, the privileged user password could be compromised. + +Removing the "telnet-server" package decreases the risk of accidental (or intentional) activation of the telnet service.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to not have the "telnet-server" package installed with the following command: + +$ sudo dnf -y remove telnet-server + + + + + + + + SRG-OS-000074-GPOS-00042 + <GroupDescription></GroupDescription> + + RHEL-10-200070 + RHEL 10 must not have the "tftp" package installed. + <VulnDiscussion>It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities are often overlooked and therefore, may remain unsecure. They increase the risk to the platform by providing additional attack vectors. + +If Trivial File Transfer Protocol (TFTP) is required for operational support (such as transmission of router configurations), its use must be documented with the information system security manager, restricted to only authorized personnel, and have access control rules established.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000197 + Configure RHEL 10 to not have the "tftp" package installed with the following command: + +$ sudo dnf -y remove tftp + + + + + + + + SRG-OS-000074-GPOS-00042 + <GroupDescription></GroupDescription> + + RHEL-10-200090 + RHEL 10 must not have a File Transfer Protocol (FTP) server package installed. + <VulnDiscussion>The FTP service provides an unencrypted remote access that does not provide for the confidentiality and integrity of user passwords or the remote session. If a privileged user were to log in using this service, the privileged user password could be compromised. Secure Shell (SSH) or other encrypted file transfer methods must be used in place of this service. + +Removing the "vsftpd" package decreases the risk of accidental activation. + +Satisfies: SRG-OS-000074-GPOS-00042, SRG-OS-000095-GPOS-00049</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000197 + CCI-000381 + Configure RHEL 10 to not have the FTP package installed with the following command (using "vsftpd" as an example): + +$ sudo dnf -y remove vsftpd + + + + + + + + SRG-OS-000370-GPOS-00155 + <GroupDescription></GroupDescription> + + RHEL-10-200601 + RHEL 10 must enable the "fapolicy" module. + <VulnDiscussion>The organization must identify authorized software programs and permit execution of authorized software. The process used to identify software programs that are authorized to execute on organizational information systems is commonly referred to as allowlisting. + +Using an allowlist provides a configuration management method for allowing the execution of only authorized software. Using only authorized software decreases risk by limiting the number of potential vulnerabilities. Verification of allowlisted software occurs prior to execution or at system startup. + +User home directories/folders may contain information of a sensitive nature. Nonprivileged users should coordinate any sharing of information with a system administrator through shared resources. + +RHEL 10 ships with many optional packages. One such package is a file access policy daemon called "fapolicyd". The "fapolicyd" is a userspace daemon that determines access rights to files based on attributes of the process and file. It can be used to either blocklist or allowlist processes or file access. + +Proceed with caution with enforcing the use of this daemon. Improper configuration may render the system nonfunctional. The "fapolicyd" application programming interface (API) is not namespace aware and can cause issues when launching or running containers. + +Satisfies: SRG-OS-000370-GPOS-00155, SRG-OS-000368-GPOS-00154</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001774 + CCI-001764 + Configure RHEL 10 to enable "fapolicyd" with the following command: + +$ systemctl enable --now fapolicyd + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-200602 + RHEL 10 must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. + <VulnDiscussion>The organization must identify authorized software programs and permit execution of authorized software. The process used to identify software programs that are authorized to execute on organizational information systems is commonly referred to as allowlisting. + +Using an allowlist provides a configuration management method for allowing the execution of only authorized software. Using only authorized software decreases risk by limiting the number of potential vulnerabilities. Verification of allowlisted software occurs prior to execution or at system startup. + +User home directories/folders may contain information of a sensitive nature. Nonprivileged users should coordinate any sharing of information with a system administrator through shared resources. + +RHEL 10 ships with many optional packages. One such package is a file access policy daemon called "fapolicyd". The "fapolicyd" is a userspace daemon that determines access rights to files based on attributes of the process and file. It can be used to either block list or allowlist processes or file access. + +Proceed with caution with enforcing the use of this daemon. Improper configuration may render the system nonfunctional. The "fapolicyd" application programming interface (API) is not namespace aware and can cause issues when launching or running containers. + +Satisfies: SRG-OS-000368-GPOS-00154, SRG-OS-000370-GPOS-00155</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + CCI-001774 + Configure RHEL 10 to employ a deny-all, permit-by-exception application allow listing policy with "fapolicyd". + +With the "fapolicyd" installed and enabled, configure the daemon to function in permissive mode until the allow list is built correctly to avoid system lockout. Do this by editing the "/etc/fapolicyd/fapolicyd.conf" file with the following line: + +permissive = 1 + +Build the allow list in a file within the "/etc/fapolicyd/rules.d" directory, ensuring the last rule implements a deny-all policy, such as "deny perm=any all : all". + +Once it is determined the allow list is built correctly, set the "fapolicyd" to enforcing mode by editing the "permissive" line in the /etc/fapolicyd/fapolicyd.conf file. + +permissive = 0 + + + + + + + + SRG-OS-000375-GPOS-00160 + <GroupDescription></GroupDescription> + + RHEL-10-200610 + RHEL 10 must have the "pcsc-lite" package installed. + <VulnDiscussion>The "pcsc-lite" package must be installed if it is to be available for multifactor authentication using smart cards.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004046 + Configure RHEL 10 to have the "pcsc-lite" package installed with the following command: + +$ sudo dnf -y install pcsc-lite + + + + + + + + SRG-OS-000375-GPOS-00160 + <GroupDescription></GroupDescription> + + RHEL-10-200611 + RHEL 10 must have the "pcscd" socket set to active. + <VulnDiscussion>The information system ensures that even if the information system is compromised, that compromise will not affect credentials stored on the authentication device. + +The daemon program for pcsc-lite and the MuscleCard framework is pcscd. It is a resource manager that coordinates communications with smart card readers and smart cards and cryptographic tokens that are connected to the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004046 + Configure RHEL 10 to have the "pcscd" socket set to active with the following command: + +$ sudo systemctl enable --now pcscd.socket + + + + + + + + SRG-OS-000375-GPOS-00160 + <GroupDescription></GroupDescription> + + RHEL-10-200612 + RHEL 10 must have the "pcsc-lite-ccid" package installed. + <VulnDiscussion>The "pcsc-lite-ccid" package must be installed if it is to be available for multifactor authentication using smart cards.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004046 + Configure RHEL 10 to have the "pcsc-lite-ccid" package installed with the following command: + +$ sudo dnf -y install pcsc-lite-ccid + + + + + + + + SRG-OS-000375-GPOS-00160 + <GroupDescription></GroupDescription> + + RHEL-10-200620 + RHEL 10 must have the "opensc" package installed. + <VulnDiscussion>The use of Personal Identity Verification (PIV) credentials facilitates standardization and reduces the risk of unauthorized access. + +The DOD has mandated the use of the common access card (CAC) to support identity management and personal authentication for systems covered under Homeland Security Presidential Directive (HSPD) 12, as well as making the CAC a primary component of layered protection for national security systems. + +Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000376-GPOS-00161</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004046 + CCI-001953 + Configure RHEL 10 to have the "opensc" package installed with the following command: + +$ sudo dnf -y install opensc + + + + + + + + SRG-OS-000104-GPOS-00051 + <GroupDescription></GroupDescription> + + RHEL-10-200621 + RHEL 10 must use the common access card (CAC) smart card driver. + <VulnDiscussion>Smart card login provides two-factor authentication stronger than that provided by a username and password combination. Smart cards leverage public key infrastructure to provide and verify credentials. Configuring the smart card driver helps to prevent the use of unauthorized smart cards. + +Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000106-GPOS-00053, SRG-OS-000107-GPOS-00054, SRG-OS-000109-GPOS-00056, SRG-OS-000108-GPOS-00055</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000764 + CCI-000766 + CCI-000765 + CCI-004045 + Configure RHEL 10 to load the CAC driver: + +$ sudo opensc-tool --set-conf-entry app:default:card_drivers:cac + +Restart the pcscd service with the following command for the changes to take effect: + +$ sudo systemctl restart pcscd + + + + + + + + SRG-OS-000445-GPOS-00199 + <GroupDescription></GroupDescription> + + RHEL-10-200630 + RHEL 10 must have the Advanced Intrusion Detection Environment (AIDE) package installed. + <VulnDiscussion>Without verification of the security functions, security functions may not operate correctly, and the failure may go unnoticed. Security function is defined as the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based. + +Security functionality includes, but is not limited to, establishing system accounts, configuring access authorizations (e.g., permissions, privileges), setting events to be audited, and setting intrusion detection parameters.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002696 + Configure RHEL 10 so that "AIDE" is installed and initialized, and then perform a manual check. + +Install AIDE: + +$ sudo dnf -y install aide + +Initialize AIDE: + +$ sudo /usr/sbin/aide --init + +Example output: + +Start timestamp: 2025-04-03 10:09:04 -0600 (AIDE 0.16) +AIDE initialized database at /var/lib/aide/aide.db.new.gz + +Number of entries: 86833 + +--------------------------------------------------- +The attributes of the (uncompressed) database(s): +--------------------------------------------------- + +/var/lib/aide/aide.db.new.gz + MD5 : coZUtPHhoFoeD7+k54fUvQ== + SHA1 : DVpOEMWJwo0uPgrKZAygIUgSxeM= + SHA256 : EQiZH0XNEk001tcDmJa+5STFEjDb4MPE + TGdBJ/uvZKc= + SHA512 : 86KUqw++PZhoPK0SZvT3zuFq9yu9nnPP + toei0nENVELJ1LPurjoMlRig6q69VR8l + +44EwO9eYyy9nnbzQsfG1g== + +End timestamp: 2025-04-03 10:09:57 -0600 (run time: 0m 53s) + +The new database must be renamed to be read by AIDE: + +$ sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz + +Perform a manual check: + +$ sudo /usr/sbin/aide --check + +Example output: + +2025-04-03 10:16:08 -0600 (AIDE 0.16) +AIDE found NO differences between database and filesystem. Looks okay!! + +... + + + + + + + + SRG-OS-000278-GPOS-00108 + <GroupDescription></GroupDescription> + + RHEL-10-200631 + RHEL 10 must use cryptographic mechanisms to protect the integrity of audit tools. + <VulnDiscussion>Protecting the integrity of the tools used for auditing purposes is a critical step toward ensuring the integrity of audit information. Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity. + +Audit tools include, but are not limited to, vendor-provided and open-source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators. + +It is not uncommon for attackers to replace the audit tools or inject code into the existing tools to provide the capability to hide or erase system activity from the audit logs. + +To address this risk, audit tools must be cryptographically signed to provide the capability to identify when the audit tools have been modified, manipulated, or replaced. An example is a checksum hash of the file or files.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001496 + Configure RHEL 10 to use cryptographic mechanisms to protect the integrity of audit tools. + +Add or update the following lines to "/etc/aide.conf" to protect the integrity of the audit tools. + +/usr/sbin/auditctl p+i+n+u+g+s+b+acl+xattrs+sha512 +/usr/sbin/auditd p+i+n+u+g+s+b+acl+xattrs+sha512 +/usr/sbin/ausearch p+i+n+u+g+s+b+acl+xattrs+sha512 +/usr/sbin/aureport p+i+n+u+g+s+b+acl+xattrs+sha512 +/usr/sbin/augenrules p+i+n+u+g+s+b+acl+xattrs+sha512 + + + + + + + + SRG-OS-000479-GPOS-00224 + <GroupDescription></GroupDescription> + + RHEL-10-200640 + RHEL 10 must have the "rsyslog" package installed. + <VulnDiscussion>The "rsyslogd" is a system utility providing support for message logging. Support for both internet and Unix domain sockets enables this utility to support local and remote logging. Couple this utility with "gnutls" (which is a secure communications library implementing the Secure Sockets Layer [SSL], Transport Layer Security [TLS], and Datagram TLS [DTLS] protocols), to create a method to securely encrypt and off-load auditing. + +Satisfies: SRG-OS-000479-GPOS-00224, SRG-OS-000051-GPOS-00024</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001851 + CCI-000154 + Configure RHEL 10 to have the "rsyslogd" package installed with the following command: + +$ sudo dnf -y install rsyslogd + + + + + + + + SRG-OS-000040-GPOS-00018 + <GroupDescription></GroupDescription> + + RHEL-10-200641 + RHEL 10 must have the rsyslog service set to active. + <VulnDiscussion>The rsyslog service must be running to provide logging services, which are essential to system administration.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000133 + Configure RHEL 10 to enable the rsyslog service with the following command: + +$ sudo systemctl enable --now rsyslog + + + + + + + + SRG-OS-000479-GPOS-00224 + <GroupDescription></GroupDescription> + + RHEL-10-200642 + RHEL 10 must be configured to forward audit records via Transmission Control Protocol (TCP) to a different system or media from the system being audited via rsyslog. + <VulnDiscussion>Information stored in one location is vulnerable to accidental or incidental deletion or alteration. + +Off-loading is a common process in information systems with limited audit storage capacity. + +RHEL 10 installation media provides "rsyslogd", a system utility providing support for message logging. Support for both internet and Unix domain sockets enables this utility to support both local and remote logging. Coupling this utility with "gnutls" (a secure communications library implementing the Secure Sockets Layer [SSL], Transport Layer Security [TLS], and Datagram TLS [DTLS] protocols) creates a method to securely encrypt and off-load auditing. + +The rsyslog provides three ways to forward message: the traditional User Datagram Protocol (UDP) transport, which is extremely lossy but standard; the plain TCP-based transport, which loses messages only during certain situations but is widely available; and the Reliable Event Logging Protocol (RELP) transport, which does not lose messages but is currently available only as part of the rsyslogd 3.15.0 and above. + +Examples of each configuration: + +UDP *.* @remotesystemname +TCP *.* @@remotesystemname +RELP *.* :omrelp:remotesystemname:2514 + +Note that a port number was given as there is no standard port for RELP.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001851 + Configure RHEL 10 to off-load audit records onto a different system or media from the system being audited via TCP using rsyslog by specifying the remote logging server in "/etc/rsyslog.conf" or "/etc/rsyslog.d/[customfile].conf" with the name or IP address of the log aggregation server. + +Using legacy "@host:port" syntax example: +*.* @@[remoteloggingserver]:[port] + +Using Rainer script example: +action( + type="omfwd" + target="logserver.example.com" + port="514" + protocol="tcp" + action.resumeRetryCount="-1" + queue.type="linkedList" + que.size="10000" +) + +Note: The Rainer script above does not contain the required encryption settings. + + + + + + + + SRG-OS-000420-GPOS-00186 + <GroupDescription></GroupDescription> + + RHEL-10-200643 + RHEL 10 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. + <VulnDiscussion>Unintentionally running a rsyslog server accepting remote messages puts the system at increased risk. Malicious rsyslog messages sent to the server could exploit vulnerabilities in the server software, introduce misleading information into the system's logs, or fill the system's storage, leading to a denial of service. + +If the system is intended to be a log aggregation server, its use must be documented with the information system security officer.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002385 + Configure RHEL 10 to not receive remote logs using rsyslog. + +Remove the lines in "/etc/rsyslog.conf" and any files in the "/etc/rsyslog.d" directory that match any of the following: + +InputTCPServerRun +UDPServerRun +RELPServerRun +module(load="imtcp") +module(load="imudp") +module(load="imrelp") +input(type="imudp" port="514") +input(type="imtcp" port="514") +input(type="imrelp" port="514") + +Restart the rsyslog daemon with the following command for the changes to take effect: + +$ sudo systemctl restart rsyslog.service + + + + + + + + SRG-OS-000032-GPOS-00013 + <GroupDescription></GroupDescription> + + RHEL-10-200647 + RHEL 10 must monitor all remote access methods. + <VulnDiscussion>Logging remote access methods can be used to trace the decrease in the risks associated with remote user access management. It can also be used to spot cyberattacks and ensure ongoing compliance with organizational policies surrounding the use of remote access methods.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000067 + Configure RHEL 10 to monitor all remote access methods. + +Add or update the following lines to the "/etc/rsyslog.conf" file or a file in "/etc/rsyslog.d": + +auth.*;authpriv.*;daemon.* /var/log/secure + +Restart the "rsyslog" service with the following command for the changes to take effect: + +$ sudo systemctl restart rsyslog.service + + + + + + + + SRG-OS-000120-GPOS-00061 + <GroupDescription></GroupDescription> + + RHEL-10-200650 + RHEL 10 must have the packages required for encrypting off-loaded audit logs installed. + <VulnDiscussion>The "rsyslog-gnutls" package provides Transport Layer Security (TLS) support for the rsyslog daemon, which enables secure remote logging.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000803 + Configure RHEL 10 to have the "rsyslog-gnutls" package installed with the following command: + +$ sudo dnf -y install rsyslog-gnutls + + + + + + + + SRG-OS-000062-GPOS-00031 + <GroupDescription></GroupDescription> + + RHEL-10-200660 + RHEL 10 must have the "audit" package installed. + <VulnDiscussion>Without establishing what type of events occurred, along with the source, location, and outcome, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. + +Audit record content that may be necessary to satisfy this requirement includes, for example, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked. + +Associating event types with detected events in audit logs provides a means of investigating an attack, recognizing resource utilization or capacity thresholds, or identifying an improperly configured RHEL 10 system. + +Satisfies: SRG-OS-000062-GPOS-00031, SRG-OS-000037-GPOS-00015, SRG-OS-000038-GPOS-00016, SRG-OS-000039-GPOS-00017, SRG-OS-000040-GPOS-00018, SRG-OS-000041-GPOS-00019, SRG-OS-000042-GPOS-00021, SRG-OS-000051-GPOS-00024, SRG-OS-000054-GPOS-00025, SRG-OS-000122-GPOS-00063, SRG-OS-000254-GPOS-00095, SRG-OS-000255-GPOS-00096, SRG-OS-000337-GPOS-00129, SRG-OS-000348-GPOS-00136, SRG-OS-000349-GPOS-00137, SRG-OS-000350-GPOS-00138, SRG-OS-000351-GPOS-00139, SRG-OS-000352-GPOS-00140, SRG-OS-000353-GPOS-00141, SRG-OS-000354-GPOS-00142, SRG-OS-000358-GPOS-00145, SRG-OS-000365-GPOS-00152, SRG-OS-000392-GPOS-00172, SRG-OS-000475-GPOS-00220</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000169 + CCI-000130 + CCI-000131 + CCI-000132 + CCI-000133 + CCI-000134 + CCI-000135 + CCI-000154 + CCI-000158 + CCI-001876 + CCI-001464 + CCI-001487 + CCI-001914 + CCI-001875 + CCI-001877 + CCI-001878 + CCI-001879 + CCI-001880 + CCI-001881 + CCI-001882 + CCI-001889 + CCI-003938 + CCI-002884 + CCI-000172 + Configure RHEL 10 to have the "audit" service package installed with the following command: + +$ sudo dnf -y install audit + + + + + + + + SRG-OS-000062-GPOS-00031 + <GroupDescription></GroupDescription> + + RHEL-10-200661 + RHEL 10 must enable the audit service. + <VulnDiscussion>Without establishing what type of events occurred, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. Ensuring the auditd service is active ensures audit records generated by the kernel are appropriately recorded. + +Additionally, a properly configured audit subsystem ensures that actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions. + +Satisfies: SRG-OS-000062-GPOS-00031, SRG-OS-000037-GPOS-00015, SRG-OS-000038-GPOS-00016, SRG-OS-000039-GPOS-00017, SRG-OS-000040-GPOS-00018, SRG-OS-000041-GPOS-00019, SRG-OS-000042-GPOS-00021, SRG-OS-000051-GPOS-00024, SRG-OS-000054-GPOS-00025, SRG-OS-000122-GPOS-00063, SRG-OS-000254-GPOS-00095, SRG-OS-000255-GPOS-00096, SRG-OS-000337-GPOS-00129, SRG-OS-000348-GPOS-00136, SRG-OS-000349-GPOS-00137, SRG-OS-000350-GPOS-00138, SRG-OS-000351-GPOS-00139, SRG-OS-000352-GPOS-00140, SRG-OS-000353-GPOS-00141, SRG-OS-000354-GPOS-00142, SRG-OS-000358-GPOS-00145, SRG-OS-000365-GPOS-00152, SRG-OS-000392-GPOS-00172, SRG-OS-000475-GPOS-00220</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000169 + CCI-000130 + CCI-000131 + CCI-000132 + CCI-000133 + CCI-000134 + CCI-000135 + CCI-000154 + CCI-000158 + CCI-001876 + CCI-001464 + CCI-001487 + CCI-001914 + CCI-001875 + CCI-001877 + CCI-001878 + CCI-001879 + CCI-001880 + CCI-001881 + CCI-001882 + CCI-001889 + CCI-003938 + CCI-002884 + CCI-000172 + Configure RHEL 10 to enable the auditd service with the following command: + +$ sudo systemctl enable --now auditd + + + + + + + + SRG-OS-000120-GPOS-00061 + <GroupDescription></GroupDescription> + + RHEL-10-200680 + RHEL 10 must have the "libreswan" package installed. + <VulnDiscussion>Providing the ability for remote users or systems to initiate a secure virtual private network connection protects information when it is transmitted over a wide area network.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000803 + Configure RHEL 10 to have the "libreswan" service package installed with the following command: + +$ sudo dnf -y install libreswan + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-200692 + RHEL 10 must be configured to prevent unrestricted mail relaying. + <VulnDiscussion>If unrestricted mail relaying is permitted, unauthorized senders could use this host as a mail relay to send spam or for other unauthorized activity.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000381 + Configure RHEL 10 so that the postfix configuration file restricts client connections to the local network with the following command: + +$ sudo postconf -e 'smtpd_client_restrictions = permit_mynetworks,reject' + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-200700 + RHEL 10 must have the "cronie" package installed. + <VulnDiscussion>The "cronie" package must be installed if it is to be available for multifactor authentication using smart cards.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to have the "cronie" package installed with the following command: + +$ sudo dnf -y install cronie + + + + + + + + SRG-OS-000423-GPOS-00187 + <GroupDescription></GroupDescription> + + RHEL-10-200721 + RHEL 10 must, for all networked systems, have and implement Secure Shell (SSH) to protect the confidentiality and integrity of transmitted and received information. + <VulnDiscussion>Without protection of the transmitted information, confidentiality and integrity may be compromised because unprotected communications can be intercepted and either read or altered. + +This requirement applies to both internal and external networks and all types of information system components from which information can be transmitted (e.g., servers, mobile devices, notebook computers, printers, copiers, scanners, and facsimile machines). Communication paths outside the physical protection of a controlled boundary are exposed to the possibility of interception and modification. + +Protecting the confidentiality and integrity of organizational information can be accomplished by physical means (e.g., employing physical distribution systems) or logical means (e.g., employing cryptographic techniques). If physical means of protection are employed, then logical means (cryptography) do not have to be employed, and vice versa. + +Satisfies: SRG-OS-000423-GPOS-00187, SRG-OS-000424-GPOS-00188, SRG-OS-000425-GPOS-00189, SRG-OS-000426-GPOS-00190</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002418 + CCI-002421 + CCI-002420 + CCI-002422 + Configure RHEL 10 to enable the sshd service by running the following command: + +$ systemctl enable --now sshd + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-200722 + RHEL 10 must have the "openssh-clients" package installed. + <VulnDiscussion>This package includes utilities to make encrypted connections and transfer files securely to Secure Shell (SSH) servers.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to have the "openssh-clients" package installed with the following command: + +$ sudo dnf -y install openssh-clients + + + + + + + + SRG-OS-000105-GPOS-00052 + <GroupDescription></GroupDescription> + + RHEL-10-200730 + RHEL 10 must have the "pkcs11-provider" package installed. + <VulnDiscussion>Without the use of multifactor authentication, the ease of access to privileged functions is greatly increased. Multifactor authentication requires using two or more factors to achieve authentication. A privileged account is defined as an information system account with authorizations of a privileged user. The DOD common access card (CAC) with DOD-approved PKI is an example of multifactor authentication. + +Satisfies: SRG-OS-000105-GPOS-00052, SRG-OS-000375-GPOS-00160, SRG-OS-000377-GPOS-00162</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000765 + CCI-004046 + CCI-001954 + Configure RHEL 10 to have the "openssl-pkcs11" package installed with the following command: + +$ sudo dnf -y install pkcs11-provider + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-200740 + RHEL 10 must have the "gnutls-utils" package installed. + <VulnDiscussion>"GnuTLS" is a secure communications library implementing the Secure Sockets Layer (SSL), Transport Layer Security (TLS), and Datagram TLS (DTLS) protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP, and other required structures. This package contains command line TLS client and server and certificate manipulation tools.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to have the "gnutls-utils" package installed with the following command: + +$ sudo dnf -y install gnutls-utils + + + + + + + + SRG-OS-000396-GPOS-00176 + <GroupDescription></GroupDescription> + + RHEL-10-300000 + RHEL 10 must have the "crypto-policies" package installed. + <VulnDiscussion>Centralized cryptographic policies simplify applying secure ciphers across an operating system and the applications that run on that operating system. Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. + +Satisfies: SRG-OS-000396-GPOS-00176, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00174</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002450 + CCI-002890 + CCI-003123 + Configure RHEL 10 to have the "crypto-policies" package installed with the following command: + +$ sudo dnf -y install crypto-policies + + + + + + + + SRG-OS-000033-GPOS-00014 + <GroupDescription></GroupDescription> + + RHEL-10-000500 + RHEL 10 must enable FIPS mode. + <VulnDiscussion>Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. The operating system must implement cryptographic modules adhering to the higher standards approved by the federal government because this provides assurance they have been tested and validated. + +Satisfies: SRG-OS-000033-GPOS-00014, SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00174, SRG-OS-000396-GPOS-00176, SRG-OS-000423-GPOS-00187, SRG-OS-000478-GPOS-00223</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000068 + CCI-000877 + CCI-001453 + CCI-002890 + CCI-003123 + CCI-002450 + CCI-002418 + Configure RHEL 10 to implement FIPS mode. + +If this check fails on an installed system, it is a permanent finding until the system is reinstalled with "fips=1" during installation. + +Red Hat 10 does not support switching to strict FIPS mode after installation. + + + + + + + + SRG-OS-000033-GPOS-00014 + <GroupDescription></GroupDescription> + + RHEL-10-300030 + RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. + <VulnDiscussion>Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + +Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganizational-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + +Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions that use asymmetric cryptography. This enables distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + +RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/openssh.config" file. + +Satisfies: SRG-OS-000033-GPOS-00014, SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00174, SRG-OS-000423-GPOS-00187</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000068 + CCI-000877 + CCI-001453 + CCI-002890 + CCI-003123 + CCI-002418 + Configure RHEL 10 SSH clients to use only ciphers employing FIPS 140-3-approved algorithms. + +Reinstall crypto-policies with the following command: + +$ sudo dnf -y reinstall crypto-policies + +Set the crypto-policy to FIPS with the following command: + +$ sudo update-crypto-policies --set FIPS +Setting system policy to FIPS + +Note: Systemwide crypto policies are applied on application startup. It is recommended to restart the system for the change of policies to fully take place. + + + + + + + + SRG-OS-000125-GPOS-00065 + <GroupDescription></GroupDescription> + + RHEL-10-300040 + RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. + <VulnDiscussion>Without cryptographic integrity protections, unauthorized users can alter information without detection. + +Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganizational-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + +Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions that use asymmetric cryptography. This enables distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + +RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/opensshserver.config" file. + +Satisfies: SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000877 + CCI-001453 + Configure RHEL 10 SSH servers to use only ciphers employing FIPS 140-3-approved algorithms. + +Reinstall crypto-policies with the following command: + +$ sudo dnf -y reinstall crypto-policies + +Set the crypto-policy to FIPS with the following command: + +$ sudo update-crypto-policies --set FIPS +Setting system policy to FIPS + +Note: Systemwide crypto policies are applied on application startup. It is recommended to restart the system for the change of policies to fully take place. + + + + + + + + SRG-OS-000125-GPOS-00065 + <GroupDescription></GroupDescription> + + RHEL-10-300050 + RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. + <VulnDiscussion>Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + +Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganizational-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + +Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions that use asymmetric cryptography. This enables distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + +RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/openssh.config" file. + +Satisfies: SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000877 + CCI-001453 + Configure RHEL 10 SSH clients to use only MACs employing FIPS 140-3-approved algorithms. + +Reinstall crypto-policies with the following command: + +$ sudo dnf -y reinstall crypto-policies + +Set the crypto-policy to FIPS with the following command: + +$ sudo update-crypto-policies --set FIPS +Setting system policy to FIPS + +Note: Systemwide crypto policies are applied on application startup. It is recommended to restart the system for the change of policies to fully take place. + + + + + + + + SRG-OS-000125-GPOS-00065 + <GroupDescription></GroupDescription> + + RHEL-10-300060 + RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. + <VulnDiscussion>Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + +Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganization-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + +Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions using asymmetric cryptography enabling distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + +RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/opensshserver.config" file. + +Satisfies: SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000877 + CCI-001453 + Configure RHEL 10 SSH servers to use only MACs employing FIPS 140-3-approved algorithms. + +Reinstall crypto-policies with the following command: + +$ sudo dnf -y reinstall crypto-policies + +Set the crypto-policy to FIPS with the following command: + +$ sudo update-crypto-policies --set FIPS +Setting system policy to FIPS + +Note: Systemwide crypto policies are applied on application startup. It is recommended to restart the system for the change of policies to fully take place. + + + + + + + + SRG-OS-000033-GPOS-00014 + <GroupDescription></GroupDescription> + + RHEL-10-300070 + RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels. + <VulnDiscussion>Overriding the systemwide cryptographic policy makes the behavior of the Libreswan service violate expectations and makes system configuration more fragmented.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000068 + Configure RHEL 10 so that Libreswan uses the systemwide cryptographic policy. + +Add the following line to "/etc/ipsec.conf": + +include /etc/crypto-policies/back-ends/libreswan.config + + + + + + + + SRG-OS-000423-GPOS-00187 + <GroupDescription></GroupDescription> + + RHEL-10-300080 + RHEL 10 must implement DOD-approved encryption in the bind package. + <VulnDiscussion>Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + +Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions using asymmetric cryptography enabling distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + +RHEL 10 incorporates systemwide crypto policies by default. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/" directory. + +Satisfies: SRG-OS-000423-GPOS-00187, SRG-OS-000426-GPOS-00190</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-002418 + CCI-002422 + Configure RHEL 10 BIND to use the systemwide cryptographic policy. + +Add the following line to the "options" section in "/etc/named.conf": + +include "/etc/crypto-policies/back-ends/bind.config"; + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400005 + RHEL 10 must be configured so that the "/etc/group" file is group-owned by "root". + <VulnDiscussion>The "/etc/group" file contains information regarding groups that are configured on the system. Protection of this file is important for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the file "/etc/group" is set to "root" by running the following command: + +$ sudo chgrp root /etc/group + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400010 + RHEL 10 must be configured so that the "/etc/group-" file is owned by "root". + <VulnDiscussion>The "/etc/group-" file is a backup file of "/etc/group", and as such contains information regarding groups that are configured on the system. Protection of this file is important for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the owner of the "/etc/group-" file is set to "root" by running the following command: + +$ sudo chown root /etc/group- + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400015 + RHEL 10 must be configured so that the "/etc/group-" file is group-owned by "root". + <VulnDiscussion>The "/etc/group-" file is a backup file of "/etc/group", and as such contains information regarding groups that are configured on the system. Protection of this file is important for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the "/etc/group-" file is set to "root" by running the following command: + +$ sudo chgrp root /etc/group- + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400020 + RHEL 10 must be configured so that the "/etc/gshadow" file is owned by "root". + <VulnDiscussion>The "/etc/gshadow" file contains group password hashes. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the owner of the file "/etc/gshadow" is set to "root" by running the following command: + +$ sudo chown root /etc/gshadow + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400025 + RHEL 10 must be configured so that the "/etc/gshadow" file is group-owned by "root". + <VulnDiscussion>The "/etc/gshadow" file contains group password hashes. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the "/etc/gshadow" file is set to "root" by running the following command: + +$ sudo chgrp root /etc/gshadow + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400030 + RHEL 10 must be configured so that the "/etc/gshadow-" file is owned by "root". + <VulnDiscussion>The "/etc/gshadow-" file is a backup of "/etc/gshadow", and as such contains group password hashes. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the owner of the "/etc/gshadow-" file is set to "root" by running the following command: + +$ sudo chown root /etc/gshadow- + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400035 + RHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root". + <VulnDiscussion>The "/etc/gshadow-" file is a backup of "/etc/gshadow", and as such contains group password hashes. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the "/etc/gshadow-" file is set to "root" by running the following command: + +$ sudo chgrp root /etc/gshadow- + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400040 + RHEL 10 must be configured so that the "/etc/passwd" file is owned by "root". + <VulnDiscussion>The "/etc/passwd" file contains information about the users that are configured on the system. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the owner of the "/etc/passwd" file is set to "root" by running the following command: + +$ sudo chown root /etc/passwd + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400045 + RHEL 10 must be configured so that the "/etc/passwd" file is group-owned by "root". + <VulnDiscussion>The "/etc/passwd" file contains information about the users that are configured on the system. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the "/etc/passwd" file is set to "root" by running the following command: + +$ sudo chgrp root /etc/passwd + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400050 + RHEL 10 must be configured so that the "/etc/passwd-" file is owned by "root". + <VulnDiscussion>The "/etc/passwd-" file is a backup file of "/etc/passwd", and as such contains information about the users that are configured on the system. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the owner of the "/etc/passwd-" file is set to "root" by running the following command: + +$ sudo chown root /etc/passwd- + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400055 + RHEL 10 must be configured so that the "/etc/passwd-" file is group-owned by "root". + <VulnDiscussion>The "/etc/passwd-" file is a backup file of "/etc/passwd", and as such contains information about the users that are configured on the system. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the "/etc/passwd-" file is set to "root" by running the following command: + +$ sudo chgrp root /etc/passwd- + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400060 + RHEL 10 must be configured so that the "/etc/shadow" file is owned by "root". + <VulnDiscussion>The "/etc/shadow" file contains the list of local system accounts and stores password hashes. Protection of this file is critical for system security. Failure to give ownership of this file to "root" provides the designated owner with access to sensitive information, which could weaken the system security posture.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the owner of the "/etc/shadow" file is set to "root" by running the following command: + +$ sudo chown root /etc/shadow + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400065 + RHEL 10 must be configured so that the "/etc/shadow" file is group-owned by "root". + <VulnDiscussion>The "/etc/shadow" file stores password hashes. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the "/etc/shadow" file is set to "root" by running the following command: + +$ sudo chgrp root /etc/shadow + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400070 + RHEL 10 must be configured so that the "/etc/shadow-" file is owned by "root". + <VulnDiscussion>The "/etc/shadow-" file is a backup file of "/etc/shadow", and as such contains the list of local system accounts and password hashes. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the owner of the "/etc/shadow-" file is set to "root" by running the following command: + +$ sudo chown root /etc/shadow- + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400075 + RHEL 10 must be configured so that the "/etc/shadow-" file is group-owned by "root". + <VulnDiscussion>The "/etc/shadow-" file is a backup file of "/etc/shadow", and as such contains the list of local system accounts and password hashes. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that the group of the "/etc/shadow-" file is set to "root" by running the following command: + +$ sudo chgrp root /etc/shadow- + + + + + + + + SRG-OS-000206-GPOS-00084 + <GroupDescription></GroupDescription> + + RHEL-10-400080 + RHEL 10 must be configured so that the "/var/log" directory is owned by "root". + <VulnDiscussion>Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + +The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001314 + Configure RHEL 10 so that the owner of the directory "/var/log" is set to "root" by running the following command: + +$ sudo chown root /var/log + + + + + + + + SRG-OS-000206-GPOS-00084 + <GroupDescription></GroupDescription> + + RHEL-10-400085 + RHEL 10 must be configured so that the "/var/log" directory is group-owned by "root". + <VulnDiscussion>Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + +The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001314 + Configure RHEL 10 so that the group owner of the directory "/var/log" is set to "root" by running the following command: + +$ sudo chgrp root /var/log + + + + + + + + SRG-OS-000206-GPOS-00084 + <GroupDescription></GroupDescription> + + RHEL-10-400090 + RHEL 10 must be configured so that the "/var/log/"messages file is owned by root. + <VulnDiscussion>Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + +The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001314 + Configure RHEL 10 so that the owner of the "/var/log/messages" file is set to "root" by running the following command: + +$ sudo chown root /var/log/messages + + + + + + + + SRG-OS-000206-GPOS-00084 + <GroupDescription></GroupDescription> + + RHEL-10-400095 + RHEL 10 must be configured so that the "/var/log/messages" file is group-owned by "root". + <VulnDiscussion>Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + +The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001314 + Configure RHEL 10 so that the group owner of the "/var/log/messages" file is set to "root" by running the following command: + +$ sudo chgrp root /var/log/messages + + + + + + + + SRG-OS-000259-GPOS-00100 + <GroupDescription></GroupDescription> + + RHEL-10-400100 + RHEL 10 must be configured so that system commands are owned by "root". + <VulnDiscussion>If RHEL 10 allowed any user to make changes to software libraries, those changes might be implemented without undergoing the appropriate testing and approvals that are part of a robust change management process. + +This requirement applies to RHEL 10 with software libraries that are accessible and configurable, as in the case of interpreted languages. Software libraries also include privileged programs that execute with escalated privileges.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001499 + Configure RHEL 10 so that the system commands are protected from unauthorized access. + +Run the following command, replacing "[FILE]" with any system command file not owned by "root". + +$ sudo chown root [FILE] + + + + + + + + SRG-OS-000256-GPOS-00097 + <GroupDescription></GroupDescription> + + RHEL-10-400305 + RHEL 10 must be configured so that audit tools are group-owned by "root". + <VulnDiscussion>Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data; therefore, protecting audit tools is necessary to prevent unauthorized operation on audit information. + +RHEL 10 systems providing tools to interface with audit information will leverage user permissions and roles identifying the user accessing the tools, and the corresponding rights the user enjoys, to make access decisions regarding the access to audit tools. + +Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators. + +Satisfies: SRG-OS-000256-GPOS-00097, SRG-OS-000257-GPOS-00098, SRG-OS-000258-GPOS-00099</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001493 + CCI-001494 + CCI-001495 + Configure RHEL 10 so that the audit tools are group-owned by "root" by running the following command: + +$ sudo chgrp root [audit_tool] + +Replace "[audit_tool]" with each audit tool not group-owned by "root". + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400315 + RHEL 10 must define default permissions for the bash shell. + <VulnDiscussion>The "umask" controls the default access mode assigned to newly created files. A "umask" of "077" limits new files to mode "600" or less permissive. Although "umask" can be represented as a four-digit number, the first digit representing special access modes is typically ignored or required to be "0". + +This requirement applies to the globally configured system defaults and the local interactive user defaults for each account on the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to define default permissions for all authenticated users using the bash shell. + +Add or edit the lines for the "umask" parameter in the "/etc/bashrc" file to "077": + +umask 077 + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400320 + RHEL 10 must define default permissions for the c shell. + <VulnDiscussion>The "umask" controls the default access mode assigned to newly created files. A "umask" of "077" limits new files to mode "600" or less permissive. Although "umask" can be represented as a four-digit number, the first digit representing special access modes is typically ignored or required to be "0". + +This requirement applies to the globally configured system defaults and the local interactive user defaults for each account on the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to define default permissions for all authenticated users using the c shell. + +Add or edit the lines for the "umask" parameter in the "/etc/csh.cshrc" file to "077": + +umask 077 + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400325 + RHEL 10 must define default permissions for all authenticated users in such a way that the user can read and modify only their own files. + <VulnDiscussion>Setting the most restrictive default permissions ensures that when new accounts are created, they do not have unnecessary access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to define default permissions for all authenticated users in such a way that the user can read and modify only their own files. + +Add or edit the lines for the "umask" parameter in the "/etc/login.defs" file to "077": + +umask 077 + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400330 + RHEL 10 must define default permissions for the system default profile. + <VulnDiscussion>The "umask" controls the default access mode assigned to newly created files. A "umask" of "077" limits new files to mode "600" or less permissive. "Although umask" can be represented as a four-digit number, the first digit representing special access modes is typically ignored or required to be "0". + +This requirement applies to the globally configured system defaults and the local interactive user defaults for each account on the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to define default permissions for all authenticated users in such a way that the user can read and modify only their own files. + +Add or edit the lines for the "umask" parameter in the "/etc/profile" file to "077": + +umask 077 + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400340 + RHEL 10 must enforce mode "0600" or less permissive for Secure Shell (SSH) private host key files. + <VulnDiscussion>If an unauthorized user obtains the private SSH host key file, the host could be impersonated.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to enforce mode "0600" for SSH private host key files with the following command: + +$ sudo chmod 0600 /etc/ssh/ssh_host*key + +Restart the SSH daemon for the changes to take effect: + +$ sudo systemctl restart sshd.service + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400345 + RHEL 10 must enforce "root" group ownership of the "/boot/grub2/grub.cfg" file. + <VulnDiscussion>The "root" group is a highly privileged group. Furthermore, the group owner of this file should not have any access privileges anyway.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to enforce group ownership of the "/boot/grub2/grub.cfg" file. + +Change the group owner of the file "/boot/grub2/grub.cfg" to "root" by running the following command: + +$ sudo chgrp root /boot/grub2/grub.cfg + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400350 + RHEL 10 must enforce "root" ownership of the "/boot/grub2/grub.cfg" file. + <VulnDiscussion>The " /boot/grub2/grub.cfg" file stores sensitive system configuration. Protection of this file is critical for system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to enforce ownership of the "/boot/grub2/grub.cfg" file. + +Change the owner of the "/boot/grub2/grub.cfg" file to "root" by running the following command: + +$ sudo chown root /boot/grub2/grub.cfg + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-400355 + RHEL 10 must prevent device files from being interpreted on file systems that contain user home directories. + <VulnDiscussion>The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + +The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to prevent device files from being interpreted on file systems that contain user home directories. + +Modify "/etc/fstab" to use the "nodev" option on the "/home" directory. + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-400360 + RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories. + <VulnDiscussion>The "nosuid" mount option causes the system to not execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories. + +Modify "/etc/fstab" to use the "nosuid" option on the "/home" directory. + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-400365 + RHEL 10 must prevent code from being executed on file systems that contain user home directories. + <VulnDiscussion>The "noexec" mount option causes the system to not execute binary files. This option must be used for mounting any file system not containing approved binary files, as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to prevent code from being executed on file systems that contain user home directories. + +Modify "/etc/fstab" to use the "noexec" option on the "/home" directory. + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-400400 + RHEL 10 must mount "/var/log/audit" with the "nodev" option. + <VulnDiscussion>The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + +The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/var/log/audit" with the "nodev" option. + +Modify "/etc/fstab" to use the "nodev" option on the "/var/log/audit" directory. + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-400405 + RHEL 10 must mount "/var/log/audit" with the "noexec" option. + <VulnDiscussion>The "noexec" mount option causes the system to not execute binary files. This option must be used for mounting any file system not containing approved binary files, as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/var/log/audit" with the "noexec" option. + +Modify "/etc/fstab" to use the "noexec" option on the "/var/log/audit" directory. + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-400410 + RHEL 10 must mount "/var/log/audit" with the "nosuid" option. + <VulnDiscussion>The "nosuid" mount option causes the system to not execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/var/log/audit" with the "nosuid" option. + +Modify "/etc/fstab" to use the "nosuid" option on the "/var/log/audit" directory. + + + + + + + + SRG-OS-000256-GPOS-00097 + <GroupDescription></GroupDescription> + + RHEL-10-400450 + RHEL 10 must enforce a mode of "0755" or less permissive for audit tools. + <VulnDiscussion>Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is necessary to prevent unauthorized operation on audit information. + +RHEL 10 systems providing tools to interface with audit information will leverage user permissions and roles identifying the user accessing the tools, and the corresponding rights the user enjoys, to make access decisions regarding the access to audit tools. + +Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators. + +Satisfies: SRG-OS-000256-GPOS-00097, SRG-OS-000257-GPOS-00098, SRG-OS-000258-GPOS-00099</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001493 + CCI-001494 + CCI-001495 + Configure RHEL 10 so that the audit tools to have a mode of "0755" by running the following command: + +$ sudo chmod 0755 [audit_tool] + +Replace "[audit_tool]" with each audit tool that has a mode more permissive than "0755". + + + + + + + + SRG-OS-000269-GPOS-00103 + <GroupDescription></GroupDescription> + + RHEL-10-500000 + RHEL 10 must enable the systemd-journald service. + <VulnDiscussion>In the event of a system failure, RHEL 10 must preserve any information necessary to determine cause of failure and return to operations with least disruption to system processes.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001665 + Configure RHEL 10 to enable the systemd-journald service. + +To enable the systemd-journald service, run the following command: + +$ sudo systemctl enable --now systemd-journald + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-500005 + RHEL 10 must enable auditing of processes that start prior to the audit daemon. + <VulnDiscussion>Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +If auditing is enabled late in the startup process, the actions of some startup processes may not be audited. Some audit systems also maintain state information available only if auditing is enabled before a given process is created.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to enable auditing of processes that start prior to the audit daemon with the following command: + +$ sudo grubby --update-kernel=ALL --args="audit=1" + +Add or modify the following line in "/etc/default/grub" to ensure the configuration survives kernel updates: + +GRUB_CMDLINE_LINUX="audit=1" + + + + + + + + SRG-OS-000062-GPOS-00031 + <GroupDescription></GroupDescription> + + RHEL-10-500010 + RHEL 10 must audit local events. + <VulnDiscussion>Without establishing what type of events occurred, along with the source, location, and outcome, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. + +If option "local_events" is not set to "yes", only events from the network will be aggregated.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000169 + Configure RHEL 10 to generate audit records for local events by adding or updating the following line in "/etc/audit/auditd.conf": + +local_events = yes + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000058-GPOS-00028 + <GroupDescription></GroupDescription> + + RHEL-10-500015 + RHEL 10 must write audit records to disk. + <VulnDiscussion>Audit data must be synchronously written to disk to ensure log integrity. This setting ensures that all audit event data is written to disk.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000163 + Configure the RHEL 10 audit system to write log files to the disk. + +Edit the "/etc/audit/auditd.conf" file and add or update the "write_logs" option to "yes": + +write_logs = yes + +Restart the audit daemon with the following command for changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000021-GPOS-00005 + <GroupDescription></GroupDescription> + + RHEL-10-500020 + RHEL 10 must log username information when unsuccessful login attempts occur. + <VulnDiscussion>Without auditing of these events, it may be harder or impossible to identify what an attacker did after an attack.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000044 + Configure RHEL 10 to log username information when unsuccessful login attempts occur. + +Enable the feature using the following command: + +$ sudo authselect enable-feature with-faillock + +Add/modify the "/etc/security/faillock.conf" file to match the following line: + +audit + + + + + + + + SRG-OS-000046-GPOS-00022 + <GroupDescription></GroupDescription> + + RHEL-10-500035 + RHEL 10 must take appropriate action when a critical audit processing failure occurs. + <VulnDiscussion>It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without this notification, the security personnel may be unaware of an impending failure of the audit capability, and system operation may be adversely affected. + +Audit processing failures include software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000139 + Configure RHEL 10 to shut down when auditing failures occur. + +Add the following line to the bottom of the "/etc/audit/rules.d/audit.rules" file: + +-f 2 + + + + + + + + SRG-OS-000343-GPOS-00134 + <GroupDescription></GroupDescription> + + RHEL-10-500040 + RHEL 10 must take action when allocated audit record storage volume reaches 75 percent of the audit record storage capacity. + <VulnDiscussion>If action is not taken when storage volume reaches 75 percent utilization, the auditing system may fail when the storage volume reaches capacity.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001855 + Configure RHEL 10 to initiate an action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity by adding/modifying the following line in the /etc/audit/auditd.conf file: + +space_left = 25% + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000039-GPOS-00017 + <GroupDescription></GroupDescription> + + RHEL-10-500045 + RHEL 10 must label all off-loaded audit logs before sending them to the central log server. + <VulnDiscussion>Enriched logging is needed to determine who, what, and when events occur on a system. Without this, determining root cause of an event will be much more difficult. + +When audit logs are not labeled before they are sent to a central log server, the audit data will not be able to be analyzed and tied back to the correct system. + +Satisfies: SRG-OS-000039-GPOS-00017, SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000132 + CCI-001851 + Configure RHEL 10 so that all off-loaded audit logs are labeled before sending them to the central log server. + +Edit the "/etc/audit/auditd.conf" file and add or update the "name_format" option: + +name_format = hostname + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000341-GPOS-00132 + <GroupDescription></GroupDescription> + + RHEL-10-500100 + RHEL 10 must allocate audit record storage capacity to store at least one week's worth of audit records. + <VulnDiscussion>To ensure RHEL 10 systems have a sufficient storage capacity in which to write the audit logs, RHEL 10 must be able to allocate audit record storage capacity. + +The task of allocating audit record storage capacity is usually performed during initial installation of RHEL 10. + +Satisfies: SRG-OS-000341-GPOS-00132, SRG-OS-000342-GPOS-00133</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001849 + CCI-001851 + Configure RHEL 10 to allocate enough storage capacity for at least one week of audit records when audit records are not immediately sent to a central audit record storage facility. + +If audit records are stored on a partition made specifically for audit records, resize the partition with sufficient space to contain one week of audit records. + +If audit records are not stored on a partition made specifically for audit records, a new partition with sufficient space must be created. + + + + + + + + SRG-OS-000343-GPOS-00134 + <GroupDescription></GroupDescription> + + RHEL-10-500105 + RHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. + <VulnDiscussion>If action is not taken when storage volume reaches 95 percent utilization, the auditing system may fail when the storage volume reaches capacity.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001855 + Configure RHEL 10 to initiate an action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity by adding/modifying the following line in the /etc/audit/auditd.conf file: + +admin_space_left = 5% + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000343-GPOS-00134 + <GroupDescription></GroupDescription> + + RHEL-10-500110 + RHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. + <VulnDiscussion>If action is not taken when storage volume reaches 95 percent utilization, the auditing system may fail when the storage volume reaches capacity.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001855 + Configure RHEL 10 auditd service to take action if allocated audit record storage volume reaching 95 percent of the repository maximum audit record storage capacity. + +Edit the following line in "/etc/audit/auditd.conf" to ensure the system is forced into single user mode if the audit record storage volume is about to reach maximum capacity: + +admin_space_left_action = single + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000342-GPOS-00133 + <GroupDescription></GroupDescription> + + RHEL-10-500115 + RHEL 10 must take appropriate action when the internal event queue is full. + <VulnDiscussion>The audit system must have an action set up in case the internal event queue becomes full so that no data is lost. Information stored in one location is vulnerable to accidental or incidental deletion or alteration. + +Off-loading is a common process in information systems with limited audit storage capacity. + +Satisfies: SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001851 + Configure RHEL 10 to take appropriate action when the internal event queue is full. + +Edit the "/etc/audit/auditd.conf" file and add or update the "overflow_action" option: + +overflow_action = syslog + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000255-GPOS-00096 + <GroupDescription></GroupDescription> + + RHEL-10-500120 + RHEL 10 must produce audit records containing information to establish the identity of any individual or process associated with the event. + <VulnDiscussion>Without establishing what type of events occurred, along with the source, location, and outcome, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. + +Audit record content that may be necessary to satisfy this requirement includes, for example, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked. + +Enriched logging aids in making sense of who, what, and when events occur on a system. Without this, determining root cause of an event will be much more difficult.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001487 + Configure RHEL 10 audit system to resolve audit information before writing to disk. + +Edit the "/etc/audit/auditd.conf" file and add or update the "log_format" option: + +log_format = ENRICHED + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000051-GPOS-00024 + <GroupDescription></GroupDescription> + + RHEL-10-500125 + RHEL 10 must periodically flush audit records to disk to ensure that audit records are not lost. + <VulnDiscussion>If option "freq" is not set to a value that requires audit records to be written to disk after a threshold number is reached, audit records may be lost.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000154 + Configure RHEL 10 to flush audit records to disk by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +freq = 100 + +Restart the audit daemon with the following command for changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000343-GPOS-00134 + <GroupDescription></GroupDescription> + + RHEL-10-500205 + RHEL 10 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. + <VulnDiscussion>If security personnel are not notified immediately when storage volume reaches 75 percent utilization, they are unable to plan for audit record storage capacity expansion.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001855 + Configure RHEL 10 to initiate an action to notify the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity by adding/modifying the following line in the "/etc/audit/auditd.conf" file. + +space_left_action = email + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000046-GPOS-00022 + <GroupDescription></GroupDescription> + + RHEL-10-500210 + RHEL 10 must notify the system administrator (SA) and/or information system security officer (ISSO) (at a minimum) of an audit processing failure. + <VulnDiscussion>It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without this notification, the security personnel may be unaware of an impending failure of the audit capability, and system operation may be adversely affected. + +Audit processing failures include software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. + +This requirement applies to each audit data storage repository (i.e., distinct information system component where audit records are stored), the centralized audit storage capacity of organizations (i.e., all audit data storage repositories combined), or both. + +Satisfies: SRG-OS-000046-GPOS-00022, SRG-OS-000343-GPOS-00134</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000139 + CCI-001855 + Configure RHEL 10 to notify the SA and/or ISSO (at a minimum) of an audit processing failure. + +Edit the following line in "/etc/audit/auditd.conf" to ensure administrators are notified via email for those situations: + +action_mail_acct = root + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000032-GPOS-00013 + <GroupDescription></GroupDescription> + + RHEL-10-500215 + RHEL 10 must log Secure Shell (SSH) connection attempts and failures to the server. + <VulnDiscussion>SSH provides several logging levels with varying amounts of verbosity. "DEBUG" is specifically not recommended other than strictly for debugging SSH communications because it provides so much data that it is difficult to identify important security information. "INFO" or "VERBOSE" level is the basic level that only records login activity of SSH users. In many situations, such as incident response, it is important to determine when a particular user was active on a system. The logout record can eliminate users who disconnected, which helps narrow the field.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000067 + Configure RHEL 10 to log connection attempts by adding or modifying the following line in "/etc/ssh/sshd_config" or in a file in "/etc/ssh/sshd_config.d": + +LogLevel VERBOSE + +Restart the SSH daemon with the following command for the settings to take effect: + +$ sudo systemctl restart sshd.service + + + + + + + + SRG-OS-000326-GPOS-00126 + <GroupDescription></GroupDescription> + + RHEL-10-500300 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "execve" system call. + <VulnDiscussion>Misuse of privileged functions, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromised information system accounts, is a serious and ongoing concern and can have significant adverse impacts on organizations. + +Auditing the use of privileged functions is one way to detect such misuse and identify the risk from insider threats and the advanced persistent threat. + +Satisfies: SRG-OS-000326-GPOS-00126, SRG-OS-000327-GPOS-00127, SRG-OS-000755-GPOS-00220</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002233 + CCI-002234 + CCI-004188 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "execve" system call. + +Add or update the following file system rules to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -k execpriv +-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k execpriv +-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -k execpriv +-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -k execpriv + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500310 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "setxattr", "fsetxattr", "lsetxattr", "removexattr", "fremovexattr", and "lremovexattr" system calls. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000458-GPOS-00203, SRG-OS-000462-GPOS-00206, SRG-OS-000463-GPOS-00207, SRG-OS-000471-GPOS-00215, SRG-OS-000474-GPOS-00219, SRG-OS-000466-GPOS-00210, SRG-OS-000468-GPOS-00212, SRG-OS-000064-GPOS-00033</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "setxattr", "fsetxattr", "lsetxattr", "removexattr", "fremovexattr", and "lremovexattr" system calls by adding or updating the following lines to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -S setxattr,fsetxattr,lsetxattr,removexattr,fremovexattr,lremovexattr -F auid>=1000 -F auid!=unset -k perm_mod +-a always,exit -F arch=b64 -S setxattr,fsetxattr,lsetxattr,removexattr,fremovexattr,lremovexattr -F auid>=1000 -F auid!=unset -k perm_mod + +-a always,exit -F arch=b32 -S setxattr,fsetxattr,lsetxattr,removexattr,fremovexattr,lremovexattr -F auid=0 -k perm_mod +-a always,exit -F arch=b64 -S setxattr,fsetxattr,lsetxattr,removexattr,fremovexattr,lremovexattr -F auid=0 -k perm_mod + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500320 + RHEL 10 must generate audit records for successful and unsuccessful uses of "umount" system calls. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "umount" command by adding or updating the following rules in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/umount -F perm=x -F auid>=1000 -F auid!=unset -k privileged-mount + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500330 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "chacl" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "chacl" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/chacl -F perm=x -F auid>=1000 -F auid!=unset -k perm_mod + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500340 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfacl" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "setfacl" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/setfacl -F perm=x -F auid>=1000 -F auid!=unset -k perm_mod + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500350 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "chcon" command. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000468-GPOS-00212, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "chcon" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/chcon -F perm=x -F auid>=1000 -F auid!=unset -k perm_mod + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500360 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "semanage" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "semanage" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/semanage -F perm=x -F auid>=1000 -F auid!=unset -k privileged-unix-update + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500370 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfiles" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "setfiles" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/setfiles -F perm=x -F auid>=1000 -F auid!=unset -k privileged-unix-update + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500380 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "setsebool" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful use of the "setsebool " command by adding or updating the following rules in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F path=/usr/sbin/setsebool -F perm=x -F auid>=1000 -F auid!=unset -F key=privileged + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500390 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000064-GPOS-00033, SRG-OS-000458-GPOS-00203, SRG-OS-000461-GPOS-00205</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful use of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls by adding or updating the following rules in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F arch=b32 -S truncate,ftruncate,creat,open,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=unset -k perm_access +-a always,exit -F arch=b64 -S truncate,ftruncate,creat,open,openat,open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=unset -k perm_access + +-a always,exit -F arch=b32 -S truncate,ftruncate,creat,open,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=unset -k perm_access +-a always,exit -F arch=b64 -S truncate,ftruncate,creat,open,openat,open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=unset -k perm_access + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500400 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "delete_module" system call. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000471-GPOS-00216, SRG-OS-000477-GPOS-00222</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful use of the "delete_module" system call by adding or updating the following rules in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F arch=b32 -S delete_module -F auid>=1000 -F auid!=unset -k module_chng +-a always,exit -F arch=b64 -S delete_module -F auid>=1000 -F auid!=unset -k module_chng + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500410 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "init_module" and "finit_module" system calls. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000471-GPOS-00216, SRG-OS-000477-GPOS-00222</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful use of the "init_module" and "finit_module" system calls by adding or updating the following rules in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F arch=b32 -S init_module,finit_module -F auid>=1000 -F auid!=unset -k module_chng +-a always,exit -F arch=b64 -S init_module,finit_module -F auid>=1000 -F auid!=unset -k module_chng + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500420 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "chage" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000468-GPOS-00212, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "chage" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/chage -F perm=x -F auid>=1000 -F auid!=unset -k privileged-chage + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500430 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "chsh" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "chsh" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/chsh -F perm=x -F auid>=1000 -F auid!=unset -k priv_cmd + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500440 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "crontab" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "crontab" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/crontab -F perm=x -F auid>=1000 -F auid!=unset -k privileged-crontab + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500450 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "gpasswd" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "gpasswd" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/gpasswd -F perm=x -F auid>=1000 -F auid!=unset -k privileged-gpasswd + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500460 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "kmod" command. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000471-GPOS-00216, SRG-OS-000477-GPOS-00222</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "kmod" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/kmod -F perm=x -F auid>=1000 -F auid!=unset -k modules + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500470 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "newgrp" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "newgrp" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/newgrp -F perm=x -F auid>=1000 -F auid!=unset -k priv_cmd + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500480 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "pam_timestamp_check" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "pam_timestamp_check" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/pam_timestamp_check -F perm=x -F auid>=1000 -F auid!=unset -k privileged-pam_timestamp_check + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500490 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "passwd" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "passwd" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/passwd -F perm=x -F auid>=1000 -F auid!=unset -k privileged-passwd + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500500 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "postdrop" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "postdrop" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/postdrop -F perm=x -F auid>=1000 -F auid!=unset -k privileged-unix-update + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500510 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "postqueue" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "postqueue" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/postqueue -F perm=x -F auid>=1000 -F auid!=unset -k privileged-unix-update + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500520 + RHEL 10 must generate audit records for successful and unsuccessful uses of the ssh-agent command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "ssh-agent" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/ssh-agent -F perm=x -F auid>=1000 -F auid!=unset -k privileged-ssh + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500530 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "ssh-keysign" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "ssh-keysign" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/libexec/openssh/ssh-keysign -F perm=x -F auid>=1000 -F auid!=unset -k privileged-ssh + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500540 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "su" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000064-GPOS-00033, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210, SRG-OS-000755-GPOS-00220</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000172 + CCI-002884 + CCI-004188 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "su" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/su -F perm=x -F auid>=1000 -F auid!=unset -k privileged-priv_change + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500550 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "sudo" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210, SRG-OS-000755-GPOS-00220</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + CCI-004188 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "sudo" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/sudo -F perm=x -F auid>=1000 -F auid!=unset -k priv_cmd + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500560 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "sudoedit" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000755-GPOS-00220</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + CCI-004188 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "sudoedit" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/bin/sudoedit -F perm=x -F auid>=1000 -F auid!=unset -k priv_cmd + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500570 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_chkpwd" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "unix_chkpwd" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid>=1000 -F auid!=unset -k privileged-unix-update + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500580 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_update" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000064-GPOS-00033, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000172 + CCI-002884 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "unix_update" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/unix_update -F perm=x -F auid>=1000 -F auid!=unset -k privileged-unix-update + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500590 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "userhelper" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "userhelper" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/userhelper -F perm=x -F auid>=1000 -F auid!=unset -k privileged-unix-update + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500600 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "usermod" command. + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "usermod" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F path=/usr/sbin/usermod -F perm=x -F auid>=1000 -F auid!=unset -k privileged-usermod + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500610 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "mount" command. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "mount" command by adding or updating the following rule in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=unset -k export +-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=unset -k export + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000477-GPOS-00222 + <GroupDescription></GroupDescription> + + RHEL-10-500620 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "init" command. + <VulnDiscussion>Misuse of the "init" command may cause availability issues for the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful uses of the "init" command by adding or updating the following rule in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F path=/usr/sbin/init -F perm=x -F auid>=1000 -F auid!=unset -k privileged-init + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000477-GPOS-00222 + <GroupDescription></GroupDescription> + + RHEL-10-500630 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "poweroff" command. + <VulnDiscussion>Misuse of the "poweroff" command may cause availability issues for the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful uses of the "poweroff" command by adding or updating the following rule in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F path=/usr/sbin/poweroff -F perm=x -F auid>=1000 -F auid!=unset -k privileged-poweroff + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000477-GPOS-00222 + <GroupDescription></GroupDescription> + + RHEL-10-500640 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "reboot" command. + <VulnDiscussion>Misuse of the "reboot" command may cause system availability issues.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful uses of the "reboot" command by adding or updating the following rule in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F path=/usr/sbin/reboot -F perm=x -F auid>=1000 -F auid!=unset -k privileged-reboot + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000477-GPOS-00222 + <GroupDescription></GroupDescription> + + RHEL-10-500650 + RHEL 10 must generate audit records for successful and unsuccessful uses of the shutdown command. + <VulnDiscussion>Misuse of the shutdown command may cause availability issues for the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful uses of the "shutdown" command by adding or updating the following rule in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F path=/usr/sbin/shutdown -F perm=x -F auid>=1000 -F auid!=unset -k privileged-shutdown + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500660 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "umount" system call. + <VulnDiscussion>The changing of file permissions could indicate that a user is attempting to gain access to information that would otherwise be disallowed. Auditing discretionary access control (DAC) modifications can facilitate the identification of patterns of abuse among both authorized and unauthorized users. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful uses of the "umount" system call by adding or updating the following rules in "/etc/audit/audit.rules" and adding the following rules to "/etc/audit/rules.d/perm_mod.rules" or updating the existing rules in files in the "/etc/audit/rules.d/" directory: + +-a always,exit -F arch=b32 -S umount -F auid>=1000 -F auid!=unset -k privileged-umount + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500670 + RHEL 10 must generate audit records for successful and unsuccessful uses of the "umount2" system call. + <VulnDiscussion>The changing of file permissions could indicate that a user is attempting to gain access to information that would otherwise be disallowed. Auditing discretionary access control (DAC) modifications can facilitate the identification of patterns of abuse among both authorized and unauthorized users. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful uses of the "umount2" system call by adding or updating the following rules in a file in "/etc/audit/rules.d": + +-a always,exit -F arch=b32 -S umount2 -F auid>=1000 -F auid!=unset -k privileged-umount +-a always,exit -F arch=b64 -S umount2 -F auid>=1000 -F auid!=unset -k privileged-umount + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000004-GPOS-00004 + <GroupDescription></GroupDescription> + + RHEL-10-500680 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers". + <VulnDiscussion>The actions taken by system administrators must be audited to keep a record of what was executed on the system, as well as for accountability purposes. Editing the "sudoers" file may be sign of an attacker trying to establish persistent methods to a system. Auditing the editing of the "sudoers" files mitigates this risk. + +Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000018 + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000015 + CCI-002884 + CCI-000172 + CCI-001403 + CCI-001404 + CCI-001405 + CCI-002130 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/etc/sudoers -F perm=wa -F key=logins +-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -F key=logins + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000004-GPOS-00004 + <GroupDescription></GroupDescription> + + RHEL-10-500700 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group". + <VulnDiscussion>In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications must be investigated for legitimacy. + +Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000018 + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000015 + CCI-002884 + CCI-000172 + CCI-001403 + CCI-001404 + CCI-001405 + CCI-002130 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/etc/group -F perm=wa -F key=identity +-a always,exit -F arch=b64 -F path=/etc/group -F perm=wa -F key=identity + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000004-GPOS-00004 + <GroupDescription></GroupDescription> + + RHEL-10-500710 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow". + <VulnDiscussion>In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + +Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000018 + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000015 + CCI-002884 + CCI-000172 + CCI-001403 + CCI-001404 + CCI-001405 + CCI-002130 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/etc/gshadow -F perm=wa -F key=identity +-a always,exit -F arch=b64 -F path=/etc/gshadow -F perm=wa -F key=identity + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000004-GPOS-00004 + <GroupDescription></GroupDescription> + + RHEL-10-500720 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/opasswd". + <VulnDiscussion>In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + +Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000018 + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000015 + CCI-002884 + CCI-000172 + CCI-001403 + CCI-001404 + CCI-001405 + CCI-002130 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/security/opasswd". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/etc/security/opasswd -F perm=wa -F key=identity +-a always,exit -F arch=b64 -F path=(/etc/security/opasswd -F perm=wa -F key=identity + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000004-GPOS-00004 + <GroupDescription></GroupDescription> + + RHEL-10-500730 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd". + <VulnDiscussion>In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + +Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221, SRG-OS-000274-GPOS-00104, SRG-OS-000275-GPOS-00105, SRG-OS-000276-GPOS-00106, SRG-OS-000277-GPOS-00107</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000018 + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000015 + CCI-002884 + CCI-000172 + CCI-001403 + CCI-001404 + CCI-001405 + CCI-002130 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/etc/passwd -F perm=wa -F key=identity +-a always,exit -F arch=b64 -F path=/etc/passwd -F perm=wa -F key=identity + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000004-GPOS-00004 + <GroupDescription></GroupDescription> + + RHEL-10-500740 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow". + <VulnDiscussion>In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + +Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000018 + CCI-000130 + CCI-000135 + CCI-000169 + CCI-000015 + CCI-002884 + CCI-000172 + CCI-001403 + CCI-001404 + CCI-001405 + CCI-002130 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/etc/shadow -F perm=wa -F key=identity +-a always,exit -F arch=b64 -F path=/etc/shadow -F perm=wa -F key=identity + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000392-GPOS-00172 + <GroupDescription></GroupDescription> + + RHEL-10-500750 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/faillock". + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Satisfies: SRG-OS-000392-GPOS-00172, SRG-OS-000470-GPOS-00214, SRG-OS-000473-GPOS-00218</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/faillock". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/var/log/faillock -F perm=wa -F key=identity +-a always,exit -F arch=b64 -F path=/var/log/faillock -F perm=wa -F key=identity + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500760 + RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/lastlog". + <VulnDiscussion>Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000473-GPOS-00218, SRG-OS-000470-GPOS-00214</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/lastlog". + +Add or update the following file system rule to "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -F path=/var/log/lastlog -F perm=wa -F key=logins +-a always,exit -F arch=b64 -F path=/var/log/lastlog -F perm=wa -F key=logins + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500780 + RHEL 10 must generate audit records for all uses of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000064-GPOS-00033, SRG-OS-000466-GPOS-00210, SRG-OS-000458-GPOS-00203</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful and unsuccessful attempts to use the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls. + +Add or update the following rules in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod + +-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,fchmodat2 -F auid>=1000 -F auid!=unset -k perm_mod + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500790 + RHEL 10 must generate audit records for all uses of the "chown", "fchown", "fchownat", and "lchown" syscalls. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000064-GPOS-00033, SRG-OS-000466-GPOS-00210, SRG-OS-000458-GPOS-00203, SRG-OS-000474-GPOS-00219</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate audit records upon successful/unsuccessful attempts to use the "chown", "fchown", "fchownat", and "lchown"" syscalls. + +Add or update the following rules in "/etc/audit/rules.d/audit.rules": + +-a always,exit -F arch=b32 -S chown,fchown,fchownat,lchown -F auid>=1000 -F auid!=unset -k perm_mod +-a always,exit -F arch=b64 -S chown,fchown,fchownat,lchown -F auid>=1000 -F auid!=unset -k perm_mod + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000037-GPOS-00015 + <GroupDescription></GroupDescription> + + RHEL-10-500810 + RHEL 10 must generate audit records for all uses of the "rename", "unlink", "rmdir", "renameat", "renameat2", and "unlinkat" system calls. + <VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + +Audit records can be generated from various components within the information system (e.g., module or policy filter). + +When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + +The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + +Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210, SRG-OS-000467-GPOS-00211, SRG-OS-000468-GPOS-00212</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000130 + CCI-000135 + CCI-000169 + CCI-002884 + CCI-000172 + Configure RHEL 10 to generate an audit event for any successful/unsuccessful use of the "rename", "unlink", "rmdir", "renameat", "renameat2", and "unlinkat" system calls by adding or updating the following rules in the "/etc/audit/rules.d/audit.rules" file: + +-a always,exit -F arch=b32 -S rename,unlink,rmdir,renameat,renameat2,unlinkat -F auid>=1000 -F auid!=unset -k delete +-a always,exit -F arch=b64 -S rename,unlink,rmdir,renameat,renameat2,unlinkat -F auid>=1000 -F auid!=unset -k delete + +Restart the audit daemon with the following command for the changes to take effect: + +$ sudo service auditd restart + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-600000 + RHEL 10 must require a boot loader superuser password. + <VulnDiscussion>To mitigate the risk of unauthorized access to sensitive information by entities that have been issued certificates by DOD-approved PKIs, all DOD systems (e.g., web servers and web portals) must be properly configured to incorporate access control methods that do not rely solely on the possession of a certificate for access. + +Successful authentication must not automatically give an entity access to an asset or security boundary. Authorization procedures and controls must be implemented to ensure each authenticated entity also has a validated and current authorization. Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Information systems use access control policies and enforcement mechanisms to implement this requirement. + +Password protection on the boot loader configuration ensures users with physical access cannot trivially alter important bootloader settings. These include which kernel to use and whether to enter single-user mode.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to require a grub bootloader password for the grub superuser account. + +Generate an encrypted grub2 password for the grub superuser account with the following command: + +$ sudo grub2-setpassword +Enter password: +Confirm password: + + + + + + + + SRG-OS-000445-GPOS-00199 + <GroupDescription></GroupDescription> + + RHEL-10-600020 + RHEL 10 must not assign an interactive login shell for system accounts. + <VulnDiscussion>Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to use system accounts.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002696 + Configure RHEL 10 so that all noninteractive accounts on the system do not have an interactive shell assigned to them. + +If the system account needs a shell assigned for mission operations, document the need with the ISSO. + +Run the following command to disable the interactive shell for a specific noninteractive user account: + +Replace <user> with the user that has a login shell. + +$ sudo usermod --shell /sbin/nologin <user> + +Do not perform the steps in this section on the root account. Doing so will cause the system to become inaccessible. + + + + + + + + SRG-OS-000076-GPOS-00044 + <GroupDescription></GroupDescription> + + RHEL-10-600100 + RHEL 10 must, for new users or password changes, have a 60-day maximum password lifetime restriction for user account passwords in "/etc/login.defs". + <VulnDiscussion>Any password, no matter how complex, can eventually be cracked; therefore, passwords must be changed periodically. If the operating system does not limit the lifetime of passwords and force users to change their passwords, there is the risk that the operating system passwords could be compromised. + +Setting the password maximum age ensures users are required to periodically change their passwords. Requiring shorter password lifetimes increases the risk of users writing down the password in a convenient location subject to physical compromise.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to enforce a 60-day maximum password lifetime. + +Add or modify the following line in the "/etc/login.defs" file: + +PASS_MAX_DAYS 60 + + + + + + + + SRG-OS-000433-GPOS-00192 + <GroupDescription></GroupDescription> + + RHEL-10-600120 + RHEL 10 must assign a home directory for local interactive user accounts upon creation. + <VulnDiscussion>If local interactive users are not assigned a valid home directory, there is no place for the storage and control of files they should own.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002824 + Configure RHEL 10 to assign home directories to all new local interactive users by setting the "CREATE_HOME" parameter in "/etc/login.defs" to "yes" as follows: + +CREATE_HOME yes + + + + + + + + SRG-OS-000104-GPOS-00051 + <GroupDescription></GroupDescription> + + RHEL-10-600130 + RHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users. + <VulnDiscussion>To ensure accountability and prevent unauthenticated access, interactive users must be identified and authenticated to prevent potential misuse and compromise of the system. + +Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000121-GPOS-00062</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000764 + CCI-000804 + Configure RHEL 10 to not allow duplicate UIDs to exist for interactive users. + +Edit the file "/etc/passwd", and provide each interactive user account that has a duplicate UID with a unique UID. + + + + + + + + SRG-OS-000104-GPOS-00051 + <GroupDescription></GroupDescription> + + RHEL-10-600150 + RHEL 10 must assign a primary group to all interactive users. + <VulnDiscussion>If a user is assigned the group identifier (GID) of a group that does not exist on the system, and a group with the GID is subsequently created, the user may have unintended rights to any files associated with the group.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000764 + Configure RHEL 10 so that all GIDs referenced in "/etc/passwd" are defined in "/etc/group". + +Edit the file "/etc/passwd" and ensure that every user's GID is a valid GID. + + + + + + + + SRG-OS-000118-GPOS-00060 + <GroupDescription></GroupDescription> + + RHEL-10-600160 + RHEL 10 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. + <VulnDiscussion>Inactive identifiers pose a risk to systems and applications because attackers may exploit an inactive identifier and potentially obtain undetected access to the system. + +Disabling inactive accounts ensures accounts that may not have been responsibly removed are not available to attackers who may have compromised their credentials. + +Owners of inactive accounts will not notice if unauthorized access to their user account has been obtained. + +Satisfies: SRG-OS-000118-GPOS-00060, SRG-OS-000590-GPOS-00110</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-003627 + CCI-003628 + Configure RHEL 10 to disable account identifiers after 35 days of inactivity after the password expiration. + +Run the following command to change the configuration for "useradd": + +$ sudo useradd -D -f 35 + +A recommendation is 35 days, but a lower value is acceptable. + + + + + + + + SRG-OS-000420-GPOS-00186 + <GroupDescription></GroupDescription> + + RHEL-10-600180 + RHEL 10 must assign a home directory to all local interactive users in the "/etc/passwd" file. + <VulnDiscussion>If local interactive users are not assigned a valid home directory, there is no place for the storage and control of files they should own.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002385 + Configure RHEL 10 interactive users to have a home directory assigned in the "/etc/passwd" file. + +Create and assign home directories to all local interactive users on RHEL 10 that do not have a home directory assigned. + + + + + + + + SRG-OS-000329-GPOS-00128 + <GroupDescription></GroupDescription> + + RHEL-10-600200 + RHEL 10 must enforce a delay of at least four seconds between login prompts following a failed login attempt. + <VulnDiscussion>Increasing the time between a failed authentication attempt and reprompting to enter credentials helps to slow a single-threaded brute-force attack.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002238 + Configure RHEL 10 to enforce a delay of at least four seconds between login prompts following a failed console login attempt. + +Modify the "/etc/login.defs" file to set the "FAIL_DELAY" parameter to "4" or greater: + +FAIL_DELAY 4 + + + + + + + + SRG-OS-000078-GPOS-00046 + <GroupDescription></GroupDescription> + + RHEL-10-600220 + RHEL 10 must enforce that passwords be created with a minimum of 15 characters. + <VulnDiscussion>The shorter the password, the lower the number of possible combinations that must be tested before the password is compromised. + +Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password. Use of more characters in a password helps to increase exponentially the time and/or resources required to compromise the password. + +RHEL 10 uses "pwquality" as a mechanism to enforce password complexity. Configurations are set in the "etc/security/pwquality.conf" file. + +The "minlen", sometimes noted as minimum length, acts as a "score" of complexity based on the credit components of the "pwquality" module. By setting the credit components to a negative value, those components will not only be required but will not count toward the total "score" of "minlen". This will enable "minlen" to require a 15-character minimum. + +The DOD minimum password requirement is 15 characters.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to enforce a minimum 15-character password length. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "minlen" parameter: + +minlen = 15 + + + + + + + + SRG-OS-000266-GPOS-00101 + <GroupDescription></GroupDescription> + + RHEL-10-600230 + RHEL 10 must enforce password complexity by requiring at least one special character to be used. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + +RHEL 10 uses "pwquality" as a mechanism to enforce password complexity. Note that to require special characters without degrading the "minlen" value, the credit value must be expressed as a negative number in "/etc/security/pwquality.conf".</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to enforce password complexity by requiring that at least one special character be used by setting the "ocredit" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "ocredit" parameter: + +ocredit = -1 + + + + + + + + SRG-OS-000070-GPOS-00038 + <GroupDescription></GroupDescription> + + RHEL-10-600240 + RHEL 10 must enforce password complexity by requiring that at least one lowercase character be used. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + +Requiring a minimum number of lowercase characters makes password guessing attacks more difficult by ensuring a larger search space.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to enforce password complexity by requiring that at least one lowercase character be used by setting the "lcredit" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "lcredit" parameter: + +lcredit = -1 + + + + + + + + SRG-OS-000069-GPOS-00037 + <GroupDescription></GroupDescription> + + RHEL-10-600250 + RHEL 10 must enforce password complexity by requiring that at least one uppercase character be used. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + +Requiring a minimum number of uppercase characters makes password guessing attacks more difficult by ensuring a larger search space. + +Satisfies: SRG-OS-000069-GPOS-00037, SRG-OS-000070-GPOS-00038</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to enforce password complexity by requiring that at least one uppercase character be used by setting the "ucredit" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "ucredit" parameter: + +ucredit = -1 + + + + + + + + SRG-OS-000072-GPOS-00040 + <GroupDescription></GroupDescription> + + RHEL-10-600260 + RHEL 10 must require the change of at least eight characters when passwords are changed. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute–force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + +Requiring a minimum number of different characters during password changes ensures that newly changed passwords should not resemble previously compromised ones. + +Note that passwords that are changed on compromised systems will still be compromised.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to require the change of at least eight of the total number of characters when passwords are changed by setting the "difok" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "difok" parameter: + +difok = 8 + + + + + + + + SRG-OS-000072-GPOS-00040 + <GroupDescription></GroupDescription> + + RHEL-10-600280 + RHEL 10 must require the maximum number of repeating characters of the same character class to be limited to four when passwords are changed. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. + +Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex a password is, the greater the number of possible combinations that must be tested before the password is compromised. + +Satisfies: SRG-OS-000072-GPOS-00040, SRG-OS-000730-GPOS-00190</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + CCI-004065 + Configure RHEL 10 to require the change of the number of repeating characters of the same character class when passwords are changed by setting the "maxclassrepeat" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "maxclassrepeat" parameter: + +maxclassrepeat = 4 + + + + + + + + SRG-OS-000072-GPOS-00040 + <GroupDescription></GroupDescription> + + RHEL-10-600290 + RHEL 10 must require that the maximum number of repeating characters be limited to three when passwords are changed. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. + +Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex a password is, the greater the number of possible combinations that must be tested before the password is compromised.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to require the change of the number of repeating consecutive characters when passwords are changed by setting the "maxrepeat" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "maxrepeat" parameter: + +maxrepeat = 3 + + + + + + + + SRG-OS-000072-GPOS-00040 + <GroupDescription></GroupDescription> + + RHEL-10-600300 + RHEL 10 must require the change of at least four character classes when passwords are changed. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. + +Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex a password is, the greater the number of possible combinations that must be tested before the password is compromised.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to require the change of at least four character classes when passwords are changed by setting the "minclass" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "minclass" parameter: + +minclass = 4 + + + + + + + + SRG-OS-000071-GPOS-00039 + <GroupDescription></GroupDescription> + + RHEL-10-600310 + RHEL 10 must enforce password complexity by requiring that at least one numeric character be used. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password is, the greater the number of possible combinations that must be tested before the password is compromised. + +Requiring digits makes password guessing attacks more difficult by ensuring a larger search space.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to enforce password complexity by requiring that at least one numeric character be used by setting the "dcredit" option. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "dcredit" parameter: + +dcredit = -1 + + + + + + + + SRG-OS-000480-GPOS-00225 + <GroupDescription></GroupDescription> + + RHEL-10-600320 + RHEL 10 must prevent the use of dictionary words for passwords. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +If RHEL 10 allows the user to select passwords based on dictionary words, this increases the chances of password compromise by increasing the opportunity for successful guesses and brute-force attacks. + +Satisfies: SRG-OS-000480-GPOS-00225, SRG-OS-000072-GPOS-00040</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to prevent the use of dictionary words for passwords. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "dictcheck" parameter: + +dictcheck=1 + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-600400 + RHEL 10 must allow only the root account to have unrestricted access to the system. + <VulnDiscussion>An account has root authority if it has a user identifier (UID) of "0". Multiple accounts with a UID of "0" afford more opportunity for potential intruders to guess a password for a privileged account. Proper configuration of sudo is recommended to afford multiple system administrators access to root privileges in an accountable manner.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 so that only the "root" account has a UID assignment of "0". + +Change the UID of any account on the system, other than "root", that has a UID of "0". + +If the account is associated with system commands or applications, the UID should be changed to one greater than "0" but less than "1000". Otherwise, assign a UID of greater than "1000" that has not already been assigned. + + + + + + + + SRG-OS-000072-GPOS-00040 + <GroupDescription></GroupDescription> + + RHEL-10-600405 + RHEL 10 must enforce password complexity rules for the "root" account. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + +Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + +Satisfies: SRG-OS-000072-GPOS-00040, SRG-OS-000071-GPOS-00039, SRG-OS-000070-GPOS-00038, SRG-OS-000266-GPOS-00101, SRG-OS-000078-GPOS-00046, SRG-OS-000480-GPOS-00225, SRG-OS-000069-GPOS-00037</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to enforce password complexity on the "root" account. + +Add or update the following line in the "/etc/security/pwquality.conf" file or a configuration file in the "/etc/security/pwquality.conf.d/" directory to contain the "enforce_for_root" parameter: + +enforce_for_root + + + + + + + + SRG-OS-000329-GPOS-00128 + <GroupDescription></GroupDescription> + + RHEL-10-600410 + RHEL 10 must automatically lock an account when three unsuccessful login attempts occur. + <VulnDiscussion>By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-force attacks, is reduced. Limits are imposed by locking the account. + +Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002238 + CCI-000044 + Configure RHEL 10 to lock an account when three unsuccessful login attempts occur. + +Add/modify the "/etc/security/faillock.conf" file to match the following line: + +deny = 3 + + + + + + + + SRG-OS-000329-GPOS-00128 + <GroupDescription></GroupDescription> + + RHEL-10-600415 + RHEL 10 must automatically lock the root account until the root account is released by an administrator when three unsuccessful login attempts occur during a 15-minute time period. + <VulnDiscussion>By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, also known as brute-forcing, is reduced. Limits are imposed by locking the account. + +Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002238 + CCI-000044 + Configure RHEL 10 to lock out the "root" account after a number of incorrect login attempts using "pam_faillock.so". + +Enable the feature using the following command: + +$ sudo authselect enable-feature with-faillock + +Edit the "/etc/security/faillock.conf" by uncommenting or adding the following line: + +even_deny_root + + + + + + + + SRG-OS-000329-GPOS-00128 + <GroupDescription></GroupDescription> + + RHEL-10-600420 + RHEL 10 must automatically lock an account when three unsuccessful login attempts occur during a 15-minute time period. + <VulnDiscussion>By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. Limits are imposed by locking the account. + +Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002238 + CCI-000044 + Configure RHEL 10 to lock out the "root" account after a number of incorrect login attempts within 15 minutes using "pam_faillock.so". + +Enable the feature using the following command: + +$ authselect enable-feature with-faillock + +Edit the "/etc/security/faillock.conf" file as follows: + +fail_interval = 900 + + + + + + + + SRG-OS-000329-GPOS-00128 + <GroupDescription></GroupDescription> + + RHEL-10-600425 + RHEL 10 must maintain an account lock until the locked account is released by an administrator. + <VulnDiscussion>By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. Limits are imposed by locking the account. + +Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002238 + CCI-000044 + Configure RHEL 10 to lock an account after three unsuccessful login attempts until released by an administrator with the following command: + +$ authselect enable-feature with-faillock + +Edit the "/etc/security/faillock.conf" file as follows: + +unlock_time = 0 + + + + + + + + SRG-OS-000021-GPOS-00005 + <GroupDescription></GroupDescription> + + RHEL-10-600430 + RHEL 10 must ensure account lockouts persist. + <VulnDiscussion>Having lockouts persist across reboots ensures that an account is unlocked only by an administrator. If the lockouts did not persist across reboots, an attacker could reboot the system to continue brute force attacks against the accounts on the system. + +Satisfies: SRG-OS-000021-GPOS-00005, SRG-OS-000329-GPOS-00128</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000044 + CCI-002238 + Configure RHEL 10 to maintain the contents of the "faillock" directory after a reboot. + +Add/modify the "/etc/security/faillock.conf" file to match the following line: + +dir = /var/log/faillock + + + + + + + + SRG-OS-000069-GPOS-00037 + <GroupDescription></GroupDescription> + + RHEL-10-600455 + RHEL 10 must not allow blank or null passwords. + <VulnDiscussion>If an account has an empty password, anyone could log in and run commands with the privileges of that account. Accounts with empty passwords must never be used in operational environments.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to prohibit the use of null passwords. + +If PAM is managed with "authselect", use the following command to remove instances of "nullok": + +$ sudo authselect enable-feature without-nullok + +Otherwise, remove any instances of the "nullok" option in the "/etc/pam.d/password-auth" and "/etc/pam.d/system-auth" files to prevent logins with empty passwords. + +Note: Manual changes to the listed file may be overwritten by the "authselect" program. + + + + + + + + SRG-OS-000069-GPOS-00037 + <GroupDescription></GroupDescription> + + RHEL-10-600460 + RHEL 10 must not have accounts configured with blank or null passwords. + <VulnDiscussion>If an account has an empty password, anyone could log in and run commands with the privileges of that account. Accounts with empty passwords should never be used in operational environments.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 so that all accounts have a password, or lock the account with the following commands: + +Perform a password reset: + +$ sudo passwd [username] + +To lock an account: + +$ sudo passwd -l [username] + + + + + + + + SRG-OS-000104-GPOS-00051 + <GroupDescription></GroupDescription> + + RHEL-10-600470 + RHEL 10 must have a unique group ID (GID) for each group in "/etc/group". + <VulnDiscussion>To ensure accountability and prevent unauthenticated access, groups must be identified uniquely to prevent potential misuse and compromise of the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000764 + Configure RHEL 10 to contain no duplicate GIDs for interactive users. + +Edit the file "/etc/group", and provide each group that has a duplicate GID with a unique GID. + + + + + + + + SRG-OS-000069-GPOS-00037 + <GroupDescription></GroupDescription> + + RHEL-10-600485 + RHEL 10 must ensure the password complexity module in the system-auth file is configured for three or fewer retries. + <VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. "pwquality" enforces complex password construction configuration and has the ability to limit brute-force attacks on the system. + +RHEL 10 uses "pwquality" as a mechanism to enforce password complexity. This is set in both of the following: + +"/etc/pam.d/password-auth" +"/etc/pam.d/system-auth" + +By limiting the number of attempts to meet the pwquality module complexity requirements before returning with an error, the system will audit abnormal attempts at password changes.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to limit the "pwquality" retry option to "3". + +Add or update the following line in the "/etc/security/pwquality.conf" file or a file in the "/etc/security/pwquality.conf.d/" directory to contain the "retry" parameter: + +retry = 3 + + + + + + + + SRG-OS-000373-GPOS-00156 + <GroupDescription></GroupDescription> + + RHEL-10-600500 + RHEL 10 must restrict the use of the "su" command. + <VulnDiscussion>The "su" program allows commands to be run with a substitute user and group ID. It is commonly used to run commands as the root user. Limiting access to such commands is considered a good security practice. + +Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000312-GPOS-00123</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002038 + CCI-002165 + Configure RHEL 10 to require users to be in the "wheel" group to run the "su" command. + +Edit the configuration file: + +$ sudo vi /etc/pam.d/su + +Add the following lines: + +auth required pam_wheel.so use_uid +$ sed '/^[[:space:]]*#[[:space:]]*auth[[:space:]]\+required[[:space:]]\+pam_wheel\.so[[:space:]]\+use_uid$/s/^[[:space:]]*#//' -i /etc/pam.d/su + +If necessary, create a "wheel" group and add administrative users to the group. + + + + + + + + SRG-OS-000373-GPOS-00156 + <GroupDescription></GroupDescription> + + RHEL-10-600510 + RHEL 10 must be configured to not bypass password requirements for privilege escalation. + <VulnDiscussion>Without reauthentication, users may access resources or perform tasks for which they do not have authorization. When operating systems provide the capability to escalate a functional capability, it is critical the user reauthenticate. + +Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002038 + Configure RHEL 10 to require users to supply a password for privilege escalation. + +Remove any occurrences of " pam_succeed_if " in the "/etc/pam.d/sudo" file. + + + + + + + + SRG-OS-000445-GPOS-00199 + <GroupDescription></GroupDescription> + + RHEL-10-600520 + RHEL 10 must restrict privilege elevation to authorized personnel. + <VulnDiscussion>If the "sudoers" file is not configured correctly, any user defined on the system can initiate privileged actions on the target system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002696 + Configure RHEL 10 to restrict privilege elevation to authorized personnel. + +Remove the following entries from the "/etc/sudoers" file or configuration file under "/etc/sudoers.d/": + +ALL ALL=(ALL) ALL +ALL ALL=(ALL:ALL) ALL + + + + + + + + SRG-OS-000373-GPOS-00156 + <GroupDescription></GroupDescription> + + RHEL-10-600530 + RHEL 10 must require users to reauthenticate for privilege escalation. + <VulnDiscussion>Without reauthentication, users may access resources or perform tasks for which they do not have authorization. + +When operating systems provide the capability to escalate a functional capability, it is critical that the user reauthenticate. + +Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002038 + Configure RHEL 10 to not allow users to execute privileged actions without authenticating. + +Remove any occurrence of "!authenticate" found in the "/etc/sudoers" file or files in the "/etc/sudoers.d" directory: + +$ sudo sed -i '/\!authenticate/ s/^/# /g' /etc/sudoers /etc/sudoers.d/* + + + + + + + + SRG-OS-000373-GPOS-00156 + <GroupDescription></GroupDescription> + + RHEL-10-600540 + RHEL 10 must require reauthentication when using the "sudo" command. + <VulnDiscussion>Without reauthentication, users may access resources or perform tasks for which they do not have authorization. + +When operating systems provide the capability to escalate a functional capability, it is critical that the organization requires the user to reauthenticate when using the "sudo" command. + +If the value is set to an integer less than "0", the user's time stamp will not expire, and the user will not have to reauthenticate for privileged actions until the user's session is terminated. + +Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002038 + Configure RHEL 10 to reauthenticate "sudo" commands after the specified timeout. + +Add the following line to "/etc/sudoers" or a file in "/etc/sudoers.d": + +Defaults timestamp_timeout=0 + + + + + + + + SRG-OS-000373-GPOS-00156 + <GroupDescription></GroupDescription> + + RHEL-10-600550 + RHEL 10 must use the invoking user's password for privilege escalation when using "sudo". + <VulnDiscussion>If the "rootpw", "targetpw", or "runaspw" flags are defined and not disabled, by default the operating system will prompt the invoking user for the "root" user password.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002038 + Configure RHEL 10 to use the invoking user's password for privilege escalation when using "sudo". + +Define the following in the Defaults section of the /etc/sudoers file or a single configuration file in the /etc/sudoers.d/ directory: + +Defaults !targetpw +Defaults !rootpw +Defaults !runaspw + + + + + + + + SRG-OS-000373-GPOS-00156 + <GroupDescription></GroupDescription> + + RHEL-10-600560 + RHEL 10 must require users to provide a password for privilege escalation. + <VulnDiscussion>Without reauthentication, users may access resources or perform tasks for which they do not have authorization. + +When operating systems provide the capability to escalate a functional capability, it is critical that the user reauthenticate. + +Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002038 + Configure RHEL 10 to not allow users to execute privileged actions without authenticating with a password. + +Remove any occurrence of "NOPASSWD" found in the "/etc/sudoers" file or files in the "/etc/sudoers.d" directory: + +$ sudo find /etc/sudoers /etc/sudoers.d -type f -exec sed -i '/NOPASSWD/ s/^/# /g' {} \; + + + + + + + + SRG-OS-000069-GPOS-00037 + <GroupDescription></GroupDescription> + + RHEL-10-600620 + RHEL 10 must ensure the password complexity module is enabled in the "password-auth" file. + <VulnDiscussion>Enabling Pluggable Authentication Module (PAM) password complexity permits enforcement of strong passwords and consequently makes the system less prone to dictionary attacks. + +Satisfies: SRG-OS-000069-GPOS-00037, SRG-OS-000070-GPOS-00038</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to use "pwquality" to enforce password complexity rules. + +Add the following line to the "/etc/pam.d/password-auth" file (or modify the line to have the required value): + +password required pam_pwquality.so + + + + + + + + SRG-OS-000069-GPOS-00037 + <GroupDescription></GroupDescription> + + RHEL-10-600630 + RHEL 10 must ensure the password complexity module is enabled in the "system-auth" file. + <VulnDiscussion>Enabling Pluggable Authentication Module (PAM) password complexity permits enforcement of strong passwords and consequently makes the system less prone to dictionary attacks.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004066 + Configure RHEL 10 to use "pwquality" to enforce password complexity rules. + +Add the following line to the "/etc/pam.d/system-auth" file (or modify the line to have the required value): + +password required pam_pwquality.so + + + + + + + + SRG-OS-000073-GPOS-00041 + <GroupDescription></GroupDescription> + + RHEL-10-600650 + RHEL 10 must ensure that the pam_unix.so module is configured in the password-auth file to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication. + <VulnDiscussion>Unapproved mechanisms that are used for authentication to the cryptographic module are not verified; therefore, they cannot be relied on to provide confidentiality or integrity, and DOD data may be compromised. + +RHEL 10 systems using encryption are required to use FIPS-compliant mechanisms for authenticating to cryptographic modules. + +FIPS 140-3 is the current standard for validating that mechanisms used to access cryptographic modules use authentication that meets DOD requirements. This allows for Security Levels 1, 2, 3, or 4 for use on a general-purpose computing system. + +Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004062 + CCI-000803 + Configure RHEL 10 to use the sha512 cryptographic hashing algorithm for local account passwords. + +Edit/modify the following line in the "/etc/pam.d/password-auth" file to include the sha512 option for pam_unix.so: + +password sufficient pam_unix.so sha512 + + + + + + + + SRG-OS-000073-GPOS-00041 + <GroupDescription></GroupDescription> + + RHEL-10-600700 + RHEL 10 must be configured to use a sufficient number of hashing rounds for the shadow password suite. + <VulnDiscussion>Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + +Using more hashing rounds makes password cracking attacks more difficult. + +Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004062 + CCI-000803 + Configure RHEL 10 to use a sufficient number of hashing rounds for shadow password suite. + +Add or modify the following line in "/etc/pam.d/system-auth" and set "rounds" to 100000: + +password sufficient pam_unix.so sha512 rounds=100000 + + + + + + + + SRG-OS-000073-GPOS-00041 + <GroupDescription></GroupDescription> + + RHEL-10-600710 + RHEL 10 must be configured to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication by ensuring that the pam_unix.so module is configured in the "system-auth" file. + <VulnDiscussion>Unapproved mechanisms that are used for authentication to the cryptographic module are not verified and therefore cannot be relied on to provide confidentiality or integrity, and DOD data may be compromised. + +RHEL 10 systems using encryption are required to use FIPS-compliant mechanisms for authenticating to cryptographic modules. + +FIPS 140-3 is the current standard for validating that mechanisms used to access cryptographic modules use authentication that meets DOD requirements. This allows for Security Levels 1, 2, 3, or 4 for use on a general-purpose computing system. + +Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004062 + CCI-000803 + Configure RHEL 10 to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication in "/etc/pam.d/system-auth" via the "pam_unix.so" module. + +Edit/modify the following line in the "/etc/pam.d/system-auth" file to include the sha512 option for pam_unix.so: + +password sufficient pam_unix.so sha512 + + + + + + + + SRG-OS-000073-GPOS-00041 + <GroupDescription></GroupDescription> + + RHEL-10-600720 + RHEL 10 must be configured so that password-auth uses a sufficient number of hashing rounds. + <VulnDiscussion>Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + +Using more hashing rounds makes password cracking attacks more difficult. + +Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004062 + CCI-000803 + Configure RHEL 10 to use "100000" hashing rounds for hashing passwords. + +Add or modify the following line in "/etc/pam.d/password-auth" and set "rounds" to "100000": + +password sufficient pam_unix.so sha512 rounds=100000 + + + + + + + + SRG-OS-000073-GPOS-00041 + <GroupDescription></GroupDescription> + + RHEL-10-600730 + RHEL 10 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords. + <VulnDiscussion>The system must use a strong hashing algorithm to store the password. + +Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. + +Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004062 + CCI-000803 + Configure RHEL 10 to employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords. + +Lock all interactive user accounts not using SHA-512 hashing until the passwords can be regenerated with SHA-512. + + + + + + + + SRG-OS-000073-GPOS-00041 + <GroupDescription></GroupDescription> + + RHEL-10-600740 + RHEL 10 must be configured to use the shadow file to store only encrypted representations of passwords. + <VulnDiscussion>Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + +This setting ensures user and group account administration utilities are configured to store only encrypted representations of passwords. Additionally, the "crypt_style" configuration option ensures the use of a strong hashing algorithm that makes password cracking attacks more difficult.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004062 + Configure RHEL 10 to store only SHA512 encrypted representations of passwords. + +Add or update the following line in the "/etc/login.defs" file: + +ENCRYPT_METHOD SHA512 + + + + + + + + SRG-OS-000073-GPOS-00041 + <GroupDescription></GroupDescription> + + RHEL-10-600750 + RHEL 10 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. + <VulnDiscussion>Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + +This setting ensures user and group account administration utilities are configured to store only encrypted representations of passwords. Additionally, the "crypt_style" configuration option ensures the use of a strong hashing algorithm that makes password cracking attacks more difficult.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-004062 + Configure RHEL 10 to use the SHA-512 algorithm for password hashing. + +Add or change the following line in the "[default]" section of the "/etc/libuser.conf" file: + +crypt_style = sha512 + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-700010 + RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a Secure Shell (SSH) login. + <VulnDiscussion>The warning message reinforces policy awareness during the login process and facilitates possible legal action against attackers. Alternatively, systems whose ownership should not be obvious should ensure use of a banner that does not provide easy attribution. + +OpenSSH uses the first occurrence of a keyword it sees, and drop-in files are read in lexicographical order at the start of the configuration. Red Hat recommends using drop-in files rather than changing base configuration files.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000213 + Configure RHEL 10 to display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via SSH. + +Edit a file in "/etc/ssh/sshd_config.d" to uncomment or add the banner keyword and configure it to point to a file that will contain the login banner (this file may be named differently or be in a different location if using a version of SSH that is provided by a third-party vendor). + +An example configuration line is: + +Banner /etc/issue + + + + + + + + SRG-OS-000023-GPOS-00006 + <GroupDescription></GroupDescription> + + RHEL-10-700030 + RHEL 10 must prevent a user from overriding the banner-message-enable setting for the graphical user interface. + <VulnDiscussion>Display of a standardized and approved use notification before granting access to the operating system ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. + +For U.S. Government systems, system use notifications are required only for access via login interfaces with human users and are not required when such human interfaces do not exist. + +Satisfies: SRG-OS-000023-GPOS-00006, SRG-OS-000228-GPOS-00088</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000048 + CCI-001384 + CCI-001385 + CCI-001386 + CCI-001387 + CCI-001388 + Configure RHEL 10 to prevent a user from overriding the banner setting for graphical user interfaces. + +Create a database to contain the systemwide graphical user login settings (if it does not already exist) with the following command: + +$ sudo vi /etc/dconf/db/local.d/locks/session + +Add the following setting to prevent nonprivileged users from modifying it: + +/org/gnome/login-screen/banner-message-enable + +Run the following command to update the database: + +$ sudo dconf update + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-700100 + RHEL 10 must prevent special devices on file systems that are imported via Network File System (NFS). + <VulnDiscussion>The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000213 + Configure RHEL 10 to prevent special devices on file systems that are imported via NFS. + +Update each NFS mounted file system to use the "nodev" option on file systems that are being imported via NFS. + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-700105 + RHEL 10 must prevent code from being executed on file systems that are imported via Network File System (NFS). + <VulnDiscussion>The "noexec" mount option causes the system not to execute binary files. This option must be used for mounting any file system not containing approved binary as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000213 + Configure RHEL 10 to prevent code from being executed on file systems that are imported via NFS. + +Update each NFS mounted file system to use the "noexec" option on file systems that are being imported via NFS. + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-700110 + RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via Network File System (NFS). + <VulnDiscussion>The "nosuid" mount option causes the system not to execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000213 + Configure RHEL 10 to prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via NFS. + +Update each NFS mounted file system to use the "nosuid" option on file systems that are being imported via NFS. + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-700115 + RHEL 10 must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS. + <VulnDiscussion>When an NFS server is configured to use RPCSEC_SYS, a selected userid and groupid are used to handle requests from the remote user. The userid and groupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS method of authentication uses certificates on the server and client systems to more securely authenticate the remote mount request.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000213 + Configure RHEL 10 so that the "/etc/fstab" file "sec" option is defined for each NFS mounted file system, and the "sec" option does not have the "sys" setting. + +Ensure the "sec" option is defined as "krb5p:krb5i:krb5". + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-700120 + RHEL 10 must mount "/boot" with the "nodev" option. + <VulnDiscussion>The only legitimate location for device files is the "/dev" directory located on the root partition. The only exception to this is chroot jails.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/boot" with the "nodev" option. + +Modify "/etc/fstab" to use the "nodev" option on the "/boot" directory. + +To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command: + +$ sudo systemctl daemon-reload + +Use the following command to apply the changes immediately without a reboot: + +$ sudo mount -o remount /boot + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-700125 + RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot" directory. + <VulnDiscussion>The "nosuid" mount option causes the system not to execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot" directory. + +Modify "/etc/fstab" to use the "nosuid" option on the "/boot" directory. + +To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command: + +$ sudo systemctl daemon-reload + +Use the following command to apply the changes immediately without a reboot: + +$ sudo mount -o remount /boot + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-700130 + RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot/efi" directory. + <VulnDiscussion>The "nosuid" mount option causes the system not to execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000213 + Configure RHEL 10 to prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot/efi" directory. + +Modify "/etc/fstab" to use the "nosuid" option on the "/boot/efi" directory. + +To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command: + +$ sudo systemctl daemon-reload + +Use the following command to apply the changes immediately without a reboot: + +$ sudo mount -o remount /boot/efi + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-700135 + RHEL 10 must mount "/dev/shm" with the "nodev" option. + <VulnDiscussion>The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + +The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/dev/shm" with the "nodev" option. + +Modify "/etc/fstab" to use the "nodev" option on the "/dev/shm" file system. + +To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command: + +$ sudo systemctl daemon-reload + +Use the following command to apply the changes immediately without a reboot: + +$ sudo mount -o remount /dev/shm + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-700140 + RHEL 10 must mount "/dev/shm" with the "noexec" option. + <VulnDiscussion>The "noexec" mount option causes the system to not execute binary files. This option must be used for mounting any file system not containing approved binary files, as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/dev/shm" with the "noexec" option. + +Modify "/etc/fstab" to use the "noexec" option on the "/dev/shm" file system. + +To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command: + +$ sudo systemctl daemon-reload + +Use the following command to apply the changes immediately without a reboot: + +$ sudo mount -o remount /dev/shm + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-700145 + RHEL 10 must mount "/dev/shm" with the "nosuid" option. + <VulnDiscussion>The "nosuid" mount option causes the system to not execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/dev/shm" with the "nosuid" option. + +Modify "/etc/fstab" to use the "nosuid" option on the "/dev/shm" file system. + +To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command: + +$ sudo systemctl daemon-reload + +Use the following command to apply the changes immediately without a reboot: + +$ sudo mount -o remount /dev/shm + + + + + + + + SRG-OS-000368-GPOS-00154 + <GroupDescription></GroupDescription> + + RHEL-10-700150 + RHEL 10 must mount "/tmp" with the "nodev" option. + <VulnDiscussion>The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + +The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001764 + Configure RHEL 10 to mount "/tmp" with the "nodev" option. + +Modify "/etc/fstab" to use the "nodev" option on the "/tmp" directory. + +To reload all implicit mount units and update the dependency graph so that new options will apply correctly at next remount, run the following command: + +$ sudo systemctl daemon-reload + +Use the following command to apply the changes immediately without a reboot: + +$ sudo mount -o remount /tmp + + + + + + + + SRG-OS-000445-GPOS-00199 + <GroupDescription></GroupDescription> + + RHEL-10-700400 + RHEL 10 must enable the SELinux targeted policy. + <VulnDiscussion>Setting the SELinux policy to "targeted" or a more specialized policy ensures the system will confine processes that are likely to be targeted for exploitation, such as network or system services. + +Note: During the development or debugging of SELinux modules, it is common to temporarily place nonproduction systems in "permissive" mode. In such temporary cases, SELinux policies should be developed, and once work is completed, the system should be reconfigured to "targeted".</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002696 + Configure RHEL 10 to use the targeted SELINUX policy. + +Edit the file "/etc/selinux/config" and add or modify the following line: + +SELINUXTYPE=targeted + +A reboot is required for the changes to take effect. + + + + + + + + SRG-OS-000324-GPOS-00125 + <GroupDescription></GroupDescription> + + RHEL-10-700410 + RHEL 10 must elevate the SELinux context when an administrator calls the sudo command. + <VulnDiscussion>Without verification of the security functions, security functions may not operate correctly and the failure may go unnoticed. Security function is defined as the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based. + +Security functionality includes, but is not limited to, establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters. + +This requirement applies to operating systems performing security function verification/testing and/or systems and environments that require this functionality. + +Preventing nonprivileged users from executing privileged functions mitigates the risk that unauthorized individuals or processes may gain unnecessary access to information or privileges. + +Privileged functions include, for example, establishing accounts, performing system integrity checks, or administering cryptographic key management activities. Nonprivileged users are individuals who do not possess appropriate authorizations. Circumventing intrusion detection and prevention mechanisms or malicious code protection mechanisms are examples of privileged functions that require protection from nonprivileged users.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002235 + Configure RHEL 10 to elevate the SELinux context when an administrator calls the sudo command. + +Edit a file in the "/etc/sudoers.d" directory with the following command: + +$ sudo visudo -f /etc/sudoers.d/ + +Use the following example to build the file in the "/etc/sudoers.d" directory to allow any administrator belonging to a designated sudoers admin group to elevate their SELinux context with the use of the sudo command: + +%{designated_group_or_user_name} ALL=(ALL) TYPE=sysadm_t ROLE=sysadm_r ALL + +Remove any configurations that conflict with the above from the following locations: + +/etc/sudoers +/etc/sudoers.d/ + + + + + + + + SRG-OS-000445-GPOS-00199 + <GroupDescription></GroupDescription> + + RHEL-10-700500 + RHEL 10 must be configured so that Secure Shell (SSH) public host key files have mode "0644" or less permissive. + <VulnDiscussion>If a public host key file is modified by an unauthorized user, the SSH service may be compromised.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002696 + Configure RHEL 10 SSH public host key files to have mode "0644" or less permissive. + +Change the mode of public host key files under "/etc/ssh" to "0644" with the following command: + +$ sudo chmod 0644 /etc/ssh/*key.pub + +Restart the SSH daemon with the following command for the changes to take effect: + +$ sudo systemctl restart sshd.service + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-700640 + RHEL 10 must not allow users to override Secure Shell (SSH) environment variables. + <VulnDiscussion>SSH environment options potentially allow users to bypass access restriction in some configurations. + +OpenSSH uses the first occurrence of a keyword it sees, and drop-in files are read in lexicographical order at the start of the configuration. Red Hat recommends using drop-in files rather than changing base configuration files.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to disable unattended or automatic login via SSH. + +In "/etc/ssh/sshd_config.d", create a drop file that will lexicographically precede 50-redhat.conf and add the following line: + +PermitUserEnvironment no + +Restart the SSH daemon with the following command for the setting to take effect: + +$ sudo systemctl restart sshd.service + + + + + + + + SRG-OS-000423-GPOS-00187 + <GroupDescription></GroupDescription> + + RHEL-10-700650 + RHEL 10 must force a frequent session key renegotiation for Secure Shell (SSH) connections to the server. + <VulnDiscussion>Without protection of the transmitted information, confidentiality and integrity may be compromised because unprotected communications can be intercepted and either read or altered. + +This requirement applies to both internal and external networks and all types of information system components from which information can be transmitted (e.g., servers, mobile devices, notebook computers, printers, copiers, scanners, and facsimile machines). Communication paths outside the physical protection of a controlled boundary are exposed to the possibility of interception and modification. + +Protecting the confidentiality and integrity of organizational information can be accomplished by physical means (e.g., employing physical distribution systems) or by logical means (e.g., employing cryptographic techniques). If physical means of protection are employed, then logical means (cryptography) do not have to be employed, and vice versa. + +Session key regeneration limits the chances of a session key becoming compromised. + +OpenSSH uses the first occurrence of a keyword it sees, and drop-in files are read in lexicographical order at the start of the configuration. Red Hat recommends using drop-in files rather than changing base configuration files. + +Satisfies: SRG-OS-000423-GPOS-00187, SRG-OS-000033-GPOS-00014, SRG-OS-000424-GPOS-00188</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002418 + CCI-000068 + CCI-002421 + Configure RHEL 10 to force a frequent session key renegotiation for SSH connections to the server. + +In "/etc/ssh/sshd_config.d", create a drop file that will lexicographically precede 50-redhat.conf and add the following line: + +RekeyLimit 1G 1h + +Restart the SSH daemon with the following command for the settings to take effect: + +$ sudo systemctl restart sshd.service + + + + + + + + SRG-OS-000080-GPOS-00048 + <GroupDescription></GroupDescription> + + RHEL-10-700720 + RHEL 10 must not allow unattended or automatic login via the graphical user interface. + <VulnDiscussion>Failure to restrict system access to authenticated users negatively impacts operating system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000213 + Configure RHEL 10 so that the GNOME desktop display manager disables automatic login. + +Update the "/etc/gdm/custom.conf" file to disable automatic login to the GNOME desktop: + +$ sudo vi /etc/gdm/custom.conf + +[daemon] +AutomaticLoginEnable=false + + + + + + + + SRG-OS-000029-GPOS-00010 + <GroupDescription></GroupDescription> + + RHEL-10-700780 + RHEL 10 must prevent a user from overriding the session lock-delay setting for the graphical user interface. + <VulnDiscussion>A session timeout lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the information system but does not log out because of the temporary nature of the absence. Rather than relying on the user to manually lock their operating system session prior to vacating the vicinity, the GNOME desktop can be configured to identify when a user's session has idled and take action to initiate the session lock. Therefore, users should not be allowed to change session settings. + +Satisfies: SRG-OS-000029-GPOS-00010, SRG-OS-000031-GPOS-00012</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000057 + CCI-000060 + Configure RHEL 10 to prevent a user from overriding settings for graphical user interfaces. + +Note: The example below is using the database "local" for the system. If the system is using another database in "/etc/dconf/profile/user", the file should be created under the appropriate subdirectory. + +Update the "/etc/dconf/db/local.d/locks/session" file to prevent nonprivileged users from modifying the lock-delay setting: + +$ sudo vi /etc/dconf/db/local.d/locks/session + +/org/gnome/desktop/screensaver/lock-delay + +Run the following command to update the database: + +$ sudo dconf update + + + + + + + + SRG-OS-000445-GPOS-00199 + <GroupDescription></GroupDescription> + + RHEL-10-700810 + RHEL 10 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. + <VulnDiscussion>A user who is at the console can reboot the system at the login screen. If restart or shutdown buttons are pressed at the login screen, this can create the risk of short-term loss of availability of systems due to reboot.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-002696 + Configure RHEL 10 to prevent a user from overriding the disable-restart-buttons setting for graphical user interfaces. + +Note: The example below is using the database "local" for the system. If the system is using another database in "/etc/dconf/profile/user", the file should be created under the appropriate subdirectory. + +Update the "/etc/dconf/db/local.d/locks/session" file to prevent nonprivileged users from modifying the disable-restart-buttons setting: + +$ sudo vi /etc/dconf/db/local.d/locks/session + +/org/gnome/login-screen/disable-restart-buttons + +Run the following command to update the database: + +$ sudo dconf update + + + + + + + + SRG-OS-000420-GPOS-00186 + <GroupDescription></GroupDescription> + + RHEL-10-700820 + RHEL 10 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. + <VulnDiscussion>A locally logged-in user who presses Ctrl-Alt-Del when at the console can reboot the system. If accidentally pressed, as could happen in the case of a mixed operating system environment, this can create the risk of short-term loss of systems' availability due to unintentional reboot.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-002385 + Configure RHEL 10 to disallow the user changing the Ctrl-Alt-Del sequence in the GNOME desktop. + +Note: The example below is using the database "local" for the system. If the system is using another database in "/etc/dconf/profile/user", the file should be created under the appropriate subdirectory. + +Update the "/etc/dconf/db/local.d/locks/session" file to prevent nonprivileged users from modifying the Ctrl-Alt-Del setting: + +$ sudo vi /etc/dconf/db/local.d/locks/session + +/org/gnome/settings-daemon/plugins/media-keys/logout + +Run the following command to update the database: + +$ sudo dconf update + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-700840 + RHEL 10 must disable the user list at login for graphical user interfaces. + <VulnDiscussion>Leaving the user list enabled is a security risk because it allows anyone with physical access to the system to enumerate known user accounts without authenticated access to the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000381 + Configure RHEL 10 to disable the user list at login for graphical user interfaces. + +Note: The example below is using the database "local" for the system. If the system is using another database in "/etc/dconf/profile/user", the file should be created under the appropriate subdirectory. + +Create a database to contain the systemwide screensaver settings (if it does not already exist) with the following command: + +$ sudo vi /etc/dconf/db/local.d/02-login-screen + +[org/gnome/login-screen] +disable-user-list=true + +Update the system databases: + +$ sudo dconf update + + + + + + + + SRG-OS-000114-GPOS-00059 + <GroupDescription></GroupDescription> + + RHEL-10-700850 + RHEL 10 must be configured to disable USB mass storage. + <VulnDiscussion>USB mass storage permits easy introduction of unknown devices, thereby facilitating malicious activity. + +Satisfies: SRG-OS-000114-GPOS-00059, SRG-OS-000378-GPOS-00163</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000778 + CCI-001958 + Configure RHEL 10 to prevent the usb-storage kernel module from being loaded. + +Add the following lines to the file "/etc/modprobe.d/usb-storage.conf" (or create "usb-storage.conf" if it does not exist): + +$ sudo vi /etc/modprobe.d/usb-storage.conf + +install usb-storage /bin/false +blacklist usb-storage + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-700860 + RHEL 10 must disable Bluetooth. + <VulnDiscussion>This requirement applies to wireless peripheral technologies (e.g., wireless mice, keyboards, displays, etc.) used with RHEL 10 systems. Wireless peripherals (e.g., Wi-Fi/Bluetooth/IR keyboards, mice and pointing devices, and near field communications [NFC]) present a unique challenge by creating an open, unsecured port on a computer. + +Wireless peripherals must meet DOD requirements for wireless data transmission and be approved for use by the authorizing official. Even though some wireless peripherals, such as mice and pointing devices, do not ordinarily carry information that must be protected, modification of communications with these wireless peripherals may be used to compromise the RHEL 10 operating system. + +Satisfies: SRG-OS-000095-GPOS-00049, SRG-OS-000300-GPOS-00118</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + CCI-001443 + Configure RHEL 10 to disable the Bluetooth adapter when not in use. + +Add the following lines to the file "/etc/modprobe.d/bluetooth.conf" (or create "bluetooth.conf" if it does not exist): + +$ sudo vi /etc/modprobe.d/bluetooth.conf + +install bluetooth /bin/false +blacklist bluetooth + +Reboot the system for the settings to take effect. + + + + + + + + SRG-OS-000114-GPOS-00059 + <GroupDescription></GroupDescription> + + RHEL-10-700880 + RHEL 10 must disable the graphical user interface automounter unless required. + <VulnDiscussion>Automatically mounting file systems permits easy introduction of unknown devices, thereby facilitating malicious activity. + +Satisfies: SRG-OS-000114-GPOS-00059, SRG-OS-000378-GPOS-00163</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + + CCI-000778 + CCI-001958 + Configure RHEL 10 GNOME to disable automated mount of removable media. + +Note: The example below is using the database "local" for the system. If the system is using another database in "/etc/dconf/profile/user", the file should be created under the appropriate subdirectory. + +Update the "/etc/dconf/db/local.d/00-security-settings" database file with the following lines: + +$ sudo vi /etc/dconf/db/local.d/00-security-settings + +[org/gnome/desktop/media-handling] +automount-open=false + +Update the dconf system databases: + +$ sudo dconf update + + + + + + + + SRG-OS-000163-GPOS-00072 + <GroupDescription></GroupDescription> + + RHEL-10-700920 + RHEL 10 must automatically exit interactive command shell user sessions after 15 minutes of inactivity. + <VulnDiscussion>Terminating an idle interactive command shell user session within a short time period reduces the window of opportunity for unauthorized personnel to take control of it when left unattended in a virtual terminal or physical console. + +Satisfies: SRG-OS-000163-GPOS-00072, SRG-OS-000029-GPOS-00010</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001133 + Configure RHEL 10 to exit interactive command shell user sessions after 10 minutes of inactivity. + +Add or edit the following line in "/etc/profile.d/tmout.sh": + +#!/bin/bash + +declare -xr TMOUT=600 + + + + + + + + SRG-OS-000163-GPOS-00072 + <GroupDescription></GroupDescription> + + RHEL-10-700930 + RHEL 10 must be configured with a timeout interval for the Secure Shell (SSH) daemon. + <VulnDiscussion>Terminating an idle SSH session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or console port that has been left unattended. In addition, quickly terminating an idle SSH session will also free up resources committed by the managed network element. + +Terminating network connections associated with communications sessions includes, for example, deallocating associated TCP/IP address/port pairs at the operating system level and deallocating networking assignments at the application level if multiple application sessions are using a single operating system-level network connection. This does not mean that the operating system terminates all sessions or network access; it only ends the inactive session and releases the resources associated with that session. + +RHEL 10 uses "/etc/ssh/sshd_config" for configurations of OpenSSH. Within the "sshd_config", the product of the values of "ClientAliveInterval" and "ClientAliveCountMax" are used to establish the inactivity threshold. + +The "ClientAliveInterval" is a timeout interval in seconds after which if no data has been received from the client, sshd will send a message through the encrypted channel to request a response from the client. + +The "ClientAliveCountMax" is the number of client alive messages that may be sent without sshd receiving any messages back from the client. If this threshold is met, sshd will disconnect the client. + +For more information on these settings and others, refer to the sshd_config man pages. + +Satisfies: SRG-OS-000163-GPOS-00072, SRG-OS-000279-GPOS-00109, SRG-OS-000395-GPOS-00175</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001133 + CCI-002361 + CCI-002891 + Configure RHEL 10 to automatically terminate all network connections associated with SSH traffic at the end of a session or after 10 minutes of inactivity. + +Note: This setting must be applied in conjunction with RHEL-10-700660 to function correctly. + +In "/etc/ssh/sshd_config.d", create a drop file that will lexicographically precede 50-redhat.conf and add the following line: + +ClientAliveInterval 600 + +Restart the SSH daemon with the following command for the changes to take effect: + +$ sudo systemctl restart sshd.service + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-700940 + RHEL 10 must not default to the graphical display manager unless approved. + <VulnDiscussion>Unnecessary service packages must not be installed to decrease the attack surface of the system. Graphical display managers have a long history of security vulnerabilities and must not be used unless approved and documented.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to boot to the command line by setting the default target to "multi-user" with the following command: + +$ sudo systemctl set-default multi-user.target + + + + + + + + SRG-OS-000324-GPOS-00125 + <GroupDescription></GroupDescription> + + RHEL-10-700950 + RHEL 10 must disable the systemd Ctrl-Alt-Delete burst key sequence. + <VulnDiscussion>A locally logged-on user who presses Ctrl-Alt-Delete when at the console can reboot the system. If accidentally pressed, as could happen in the case of a mixed operating system environment, this can create the risk of short-term loss of availability of systems due to unintentional reboot. + +In a graphical user environment, risk of unintentional reboot from the Ctrl-Alt-Delete sequence is reduced because the user will be prompted before any action is taken.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002235 + Configure RHEL 10 to disable the "CtrlAltDelBurstAction". + +Update the "/etc/systemd/system.conf" configuration file as follows: + +$ sudo vi /etc/systemd/system.conf + +CtrlAltDelBurstAction=none + +Reload the daemon for this change to take effect: + +$ sudo systemctl daemon-reload + + + + + + + + SRG-OS-000324-GPOS-00125 + <GroupDescription></GroupDescription> + + RHEL-10-700960 + RHEL 10 must disable the x86 Ctrl-Alt-Delete key sequence. + <VulnDiscussion>A locally logged-on user who presses Ctrl-Alt-Delete when at the console can reboot the system. If accidentally pressed, as could happen in the case of a mixed operating system environment, this can create the risk of short-term loss of systems availability due to unintentional reboot. + +In a graphical user environment, risk of unintentional reboot from the Ctrl-Alt-Delete sequence is reduced because the user will be prompted before any action is taken.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002235 + Configure RHEL 10 to disable the "ctrl-alt-del.target" with the following command: + +$ sudo systemctl disable --now ctrl-alt-del.target +$ sudo systemctl mask --now ctrl-alt-del.target + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-700980 + RHEL 10 must disable the ability of systemd to spawn an interactive boot process. + <VulnDiscussion>Using interactive or recovery boot, the console user could disable auditing, firewalls, or other services, weakening system security.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 so that the current GRUB 2 configuration disables the ability of systemd to spawn an interactive boot process with the following command: + +$ sudo grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn" + + + + + + + + SRG-OS-000134-GPOS-00068 + <GroupDescription></GroupDescription> + + RHEL-10-700990 + RHEL 10 must disable virtual system calls. + <VulnDiscussion>System calls are special routines in the Linux kernel, which userspace applications ask to do privileged tasks. Invoking a system call is an expensive operation because the processor must interrupt the currently executing task and switch context to kernel mode and then back to userspace after the system call completes. Virtual system calls map into user space a page that contains some variables and the implementation of some system calls. This allows the system calls to be executed in userspace to alleviate the context-switching expense. + +Virtual system calls provide an opportunity of attack for a user who has control of the return instruction pointer. Disabling virtual system calls help to prevent return-oriented programming attacks via buffer overflows and overruns.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001084 + Configure RHEL 10 to disable virtual system calls with the following command: + +$ sudo grubby --update-kernel=ALL --args="vsyscall=none" + + + + + + + + SRG-OS-000134-GPOS-00068 + <GroupDescription></GroupDescription> + + RHEL-10-701000 + RHEL 10 must clear the page allocator to prevent use-after-free attacks. + <VulnDiscussion>Poisoning writes an arbitrary value to freed pages, so any modification or reference to that page after being freed or before being initialized will be detected and prevented. This prevents many types of use-after-free vulnerabilities at little performance cost. It also prevents data leakage and detection of corrupted memory.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001084 + Configure RHEL 10 to enable page poisoning with the following commands: + +$ sudo grubby --update-kernel=ALL --args="page_poison=1" + + + + + + + + SRG-OS-000134-GPOS-00068 + <GroupDescription></GroupDescription> + + RHEL-10-701010 + RHEL 10 must clear memory when it is freed to prevent use-after-free attacks. + <VulnDiscussion>Some adversaries launch attacks with the intent of executing code in nonexecutable regions of memory or in memory locations that are prohibited. Security safeguards employed to protect memory include, for example, data execution prevention and address space layout randomization. Data execution prevention safeguards can be either hardware-enforced or software-enforced, with hardware providing the greater strength of mechanism. + +Poisoning writes an arbitrary value to freed pages, so any modification or reference to that page after being freed or before being initialized will be detected and prevented. This prevents many types of use-after-free vulnerabilities at little performance cost. It also prevents data leakage and detection of corrupted memory. + +"init_on_free" is a Linux kernel boot parameter that enhances security by initializing memory regions when they are freed, preventing data leakage. This process ensures that stale data in freed memory cannot be accessed by malicious programs. + +SLUB canaries add a randomized value (canary) at the end of SLUB-allocated objects to detect memory corruption caused by buffer overflows or underflows. Redzoning adds padding (red zones) around SLUB-allocated objects to detect overflows or underflows by triggering a fault when adjacent memory is accessed. SLUB canaries are often more efficient and provide stronger detection against buffer overflows compared to redzoning. SLUB canaries are supported in hardened Linux kernels such as the ones provided by Linux-hardened. + +SLAB objects are blocks of physically contiguous memory. SLUB is the unqueued SLAB allocator.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001084 + Configure RHEL 10 to enable "init_on_free" with the following command: + +$ sudo grubby --update-kernel=ALL --args="init_on_free=1" + + + + + + + + SRG-OS-000433-GPOS-00193 + <GroupDescription></GroupDescription> + + RHEL-10-701020 + RHEL 10 must enable mitigations against processor-based vulnerabilities. + <VulnDiscussion>Kernel page-table isolation is a kernel feature that mitigates the Meltdown security vulnerability and hardens the kernel against attempts to bypass kernel address space layout randomization (KASLR). + +Satisfies: SRG-OS-000433-GPOS-00193, SRG-OS-000095-GPOS-00049</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002824 + CCI-000381 + Configure RHEL 10 to enable kernel page-table isolation with the following command: + +$ sudo grubby --update-kernel=ALL --args="pti=on" + + + + + + + + SRG-OS-000132-GPOS-00067 + <GroupDescription></GroupDescription> + + RHEL-10-701030 + RHEL 10 must restrict access to the kernel message buffer. + <VulnDiscussion>Preventing unauthorized information transfers mitigates the risk of information, including encrypted representations of information, produced by the actions of prior users/roles (or the actions of processes acting on behalf of prior users/roles) from being available to any current users/roles (or current processes) that obtain access to shared system resources (e.g., registers, main memory, hard disks) after those resources have been released back to information systems. The control of information in shared resources is also commonly referred to as object reuse and residual information protection. + +This requirement generally applies to the design of an information technology product, but it can also apply to the configuration of information system components that are, or use, such products. This can be verified by acceptance/validation processes in DOD or other government agencies. + +There may be shared resources with configurable protections (e.g., files in storage) that may be assessed on specific information system components. + +Restricting access to the kernel message buffer limits access to only root. This prevents attackers from gaining additional system information as a nonprivileged user. + +Satisfies: SRG-OS-000132-GPOS-00067, SRG-OS-000138-GPOS-00069</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001082 + CCI-001090 + Configure RHEL 10 to restrict access to the kernel message buffer. + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/sysctl.d/99-dmesg_restrict.conf + +Add the following to the file: + +kernel.dmesg_restrict = 1 + +Reload settings from all system configuration files with the following command: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000132-GPOS-00067 + <GroupDescription></GroupDescription> + + RHEL-10-701040 + RHEL 10 must prevent kernel profiling by nonprivileged users. + <VulnDiscussion>Preventing unauthorized information transfers mitigates the risk of information, including encrypted representations of information, produced by the actions of prior users/roles (or the actions of processes acting on behalf of prior users/roles) from being available to any current users/roles (or current processes) that obtain access to shared system resources (e.g., registers, main memory, hard disks) after those resources have been released back to information systems. The control of information in shared resources is also commonly referred to as object reuse and residual information protection. + +This requirement generally applies to the design of an information technology product, but it can also apply to the configuration of information system components that are, or use, such products. This can be verified by acceptance/validation processes in DOD or other government agencies. + +There may be shared resources with configurable protections (e.g., files in storage) that may be assessed on specific information system components. + +Setting the "kernel.perf_event_paranoid" kernel parameter to "2" prevents attackers from gaining additional system information as a nonprivileged user. + +Satisfies: SRG-OS-000132-GPOS-00067, SRG-OS-000138-GPOS-00069</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001082 + CCI-001090 + Configure RHEL 10 to prevent kernel profiling by nonprivileged users. + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/sysctl.d/99-kernel_perf_event_paranoid.conf + +Add the following to the file: + +kernel.perf_event_paranoid = 2 + +Reload settings from all system configuration files with the following command: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000366-GPOS-00153 + <GroupDescription></GroupDescription> + + RHEL-10-701050 + RHEL 10 must prevent the loading of a new kernel for later execution. + <VulnDiscussion>Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and has been provided by a trusted vendor. + +Disabling kexec_load prevents an unsigned kernel image (that could be a windows kernel or modified vulnerable kernel) from being loaded. Kexec can be used to subvert the entire secureboot process and should be avoided at all costs, especially because it can load unsigned kernel images.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-003992 + Configure RHEL 10 to disable kernel image loading. + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/sysctl.d/99-kernel_kexec_load_disabled.conf + +Add the following to the file: + +kernel.kexec_load_disabled = 1 + +Reload settings from all system configuration files with the following command: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000132-GPOS-00067 + <GroupDescription></GroupDescription> + + RHEL-10-701060 + RHEL 10 must restrict exposed kernel pointer address access. + <VulnDiscussion>Exposing kernel pointers (through procfs or "seq_printf()") exposes kernel writable structures, which may contain functions pointers. If a write vulnerability occurs in the kernel, allowing write access to any of this structure, the kernel can be compromised. This option disallows any program without the CAP_SYSLOG capability to get the addresses of kernel pointers by replacing them with "0". + +Satisfies: SRG-OS-000132-GPOS-00067, SRG-OS-000433-GPOS-00192</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-001082 + CCI-002824 + Configure RHEL 10 to restrict exposed kernel pointer address access. + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/sysctl.d/99-kernel_kptr_restrict.conf + +Add the following to the file: + +kernel.kptr_restrict = 1 + +Reload settings from all system configuration files with the following command: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000312-GPOS-00122 + <GroupDescription></GroupDescription> + + RHEL-10-701070 + RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on hardlinks. + <VulnDiscussion>By enabling the "fs.protected_hardlinks" kernel parameter, users can no longer create soft or hard links to files they do not own. Disallowing such hardlinks mitigates vulnerabilities based on insecure file systems accessed by privileged programs, avoiding an exploitation vector exploiting unsafe use of open() or creat(). + +Satisfies: SRG-OS-000312-GPOS-00122, SRG-OS-000312-GPOS-00123, SRG-OS-000324-GPOS-00125</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002165 + CCI-002235 + Configure RHEL 10 to enable DAC on hardlinks. + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/sysctl.d/99-fs_protected_hardlinks.conf + +Add the following to the file: + +fs.protected_hardlinks = 1 + +Reload settings from all system configuration files with the following command: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000312-GPOS-00122 + <GroupDescription></GroupDescription> + + RHEL-10-701080 + RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks. + <VulnDiscussion>By enabling the "fs.protected_symlinks" kernel parameter, symbolic links are permitted to be followed only when outside a sticky world-writable directory, or when the user identifier (UID) of the link and follower match, or when the directory owner matches the symlink's owner. Disallowing such symlinks helps mitigate vulnerabilities based on insecure file systems accessed by privileged programs, avoiding an exploitation vector exploiting unsafe use of open() or creat(). + +Satisfies: SRG-OS-000312-GPOS-00122, SRG-OS-000312-GPOS-00123, SRG-OS-000324-GPOS-00125</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002165 + CCI-002235 + Configure RHEL 10 to enable DAC on symlinks with the following: + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/sysctl.d/99-fs_protected_symlinks.conf + +Add the following to the file: + +fs.protected_symlinks = 1 + +Reload settings from all system configuration files with the following command: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-701090 + RHEL 10 must disable the "kernel.core_pattern". + <VulnDiscussion>A core dump includes a memory image taken at the time the operating system terminates an application. The memory image could contain sensitive data and is generally useful only for developers trying to debug problems.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to disable storing core dumps. + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/sysctl.d/99-kernel_core_pattern.conf + +Add the following to the file: + +kernel.core_pattern = |/bin/false + +Reload settings from all system configuration files with the following command: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000095-GPOS-00049 + <GroupDescription></GroupDescription> + + RHEL-10-701100 + RHEL 10 must be configured to disable the Controller Area Network (CAN) kernel module. + <VulnDiscussion>Disabling CAN protects the system against exploitation of any flaws in its implementation.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-000381 + Configure RHEL 10 to disable the ability to load the CAN kernel module. + +Create a drop-in if it does not already exist: + +$ sudo vi /etc/modprobe.d/can.conf + +Add the following lines to the file: + +install can /bin/false +blacklist can + + + + + + + + SRG-OS-000433-GPOS-00193 + <GroupDescription></GroupDescription> + + RHEL-10-701130 + RHEL 10 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. + <VulnDiscussion>ASLR makes it more difficult for an attacker to predict the location of attack code they have introduced into a process's address space during an attempt at exploitation. Additionally, ASLR makes it more difficult for an attacker to know the location of existing code to repurpose it using return-oriented programming techniques.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-002824 + Configure RHEL 10 to implement ASLR. + +$ echo 'kernel.randomize_va_space = 2' | sudo tee /etc/sysctl.d/99-kernel_randomize_va_space.conf + +Remove any configurations that conflict with the above from the following locations: + +/run/sysctl.d/*.conf +/usr/local/lib/sysctl.d/*.conf +/usr/lib/sysctl.d/*.conf +/lib/sysctl.d/*.conf +/etc/sysctl.conf +/etc/sysctl.d/*.conf + +Issue the following command to make the changes take effect: + +$ sudo sysctl --system + + + + + + + + SRG-OS-000830-GPOS-00300 + <GroupDescription></GroupDescription> + + RHEL-10-001000 + RHEL 10 must be a vendor-supported release. + <VulnDiscussion>An operating system release is considered "supported" if the vendor continues to provide security patches for the product. With an unsupported release, it will not be possible to resolve security issues discovered in the system software. + +Red Hat offers the Extended Update Support (EUS) add-on to a Red Hat Enterprise Linux subscription, for a fee, for customers who wish to standardize on a specific minor release for an extended period. + +End-of-life dates for Red Hat Linux 10 releases are as follows: +- Current end of Full Support for Red Hat Linux 10 is 31 May 2030. +- Current end of Maintenance Support for Red Hat Linux 10 is 31 May 2035. +- Current end of Extended Life Cycle Support (ELS) for Red Hat Linux 9 is 31 May 2038.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> + + DPMS Target Red Hat Enterprise Linux 10 + DISA + DPMS Target + Red Hat Enterprise Linux 10 + 5733 + + CCI-003376 + Upgrade to a supported version of RHEL 10. + + + + + + + + + + + + Security Content Tool 1.9.1 + 5.11 + 2026-08-25T11:17:20 + + + + + The operating system must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. + + + + + + + + + + The operating system must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS. + + + + + + + + + + + The operating system must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm. + + + + + + + + + The operating system must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords. + + + + + + + + + The operating system pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication. + + + + + + + + + The operating system /var/log/messages file must be owned by root. + + + + + + + + + The operating system /var/log/messages file must be group-owned by root. + + + + + + + + + The operating system /var/log directory must be owned by root. + + + + + + + + + The operating system /var/log directory must be group-owned by root. + + + + + + + + + The operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. + + + + + + + + + + The operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. + + + + + + + + + The operating system must require users to provide a password for privilege escalation. + + + + + + + + + + The operating system must clear the page allocator to prevent use-after-free attacks. + + + + + + + + + + The operating system must disable virtual syscalls. + + + + + + + + + + The operating system must clear memory when it is freed to prevent use-after-free attacks. + + + + + + + + + + The operating system must enable the SELinux targeted policy. + + + + + + + + + + The operating system SSH public host key files must have mode 0644 or less permissive. + + + + + + + + + The operating system must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. + + + + + + + + + The operating system must prevent files with the setuid and setgid bit set from being executed on the /boot directory. + + + + + + + + + + The operating system must prevent code from being executed on file systems that are imported via Network File System (NFS). + + + + + + + + + The operating system must prevent special devices on file systems that are imported via Network File System (NFS). + + + + + + + + + The operating system must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS). + + + + + + + + + The operating system must disable the kernel.core_pattern. + + + + + + + + + All the operating system local interactive user accounts must be assigned a home directory upon creation. + + + + + + + + + A separate operating system filesystem must be used for user home directories (such as /home or an equivalent). + + + + + + + + + Unattended or automatic logon via the operating system graphical user interface must not be allowed. + + + + + + + + + The operating system must automatically lock an account when three unsuccessful logon attempts occur. + + + + + + + + + The operating system must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. + + + + + + + + + The operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. + + + + + + + + + The operating system must ensure account lockouts persist + + + + + + + + + The operating system must log user name information when unsuccessful logon attempts occur. + + + + + + + + + The operating system must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. + + + + + + + + + The operating system must ensure the password complexity module is enabled in the password-auth file. + + + + + + + + + The operating system must enforce password complexity by requiring that at least one uppercase character be used. + + + + + + + + + The operating system must enforce password complexity by requiring that at least one lower-case character be used. + + + + + + + + + The operating system must enforce password complexity by requiring that at least one numeric character be used. + + + + + + + + + The operating system must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. + + + + + + + + + The operating system must require the maximum number of repeating characters be limited to three when passwords are changed. + + + + + + + + + The operating system must require the change of at least four character classes when passwords are changed. + + + + + + + + + The operating system must require the change of at least 8 characters when passwords are changed. + + + + + + + + + The operating system passwords must have a minimum of 15 characters. + + + + + + + + + The operating system account identifiers (individuals, groups, roles, and devices) must be disabled after 35 days of inactivity. + + + + + + + + + All the operating system passwords must contain at least one special character. + + + + + + + + + The operating system must prevent the use of dictionary words for passwords. + + + + + + + + + The operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. + + + + + + + + + The operating system must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. + + + + + + + + + The operating system audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software. + + + + + + + + + + + + The operating system System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event. + + + + + + + + + The operating system audit system must audit local events. + + + + + + + + + The operating system must label all off-loaded audit logs before sending them to the central log server. + + + + + + + + + The operating system must resolve audit information before writing to disk. + + + + + + + + + The operating system audit package must be installed. + + + + + + + + + Successful/unsuccessful uses of the su command in the operating system must generate an audit record. + + + + + + + + + The operating system audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. + + + + + + + + + + + + + + + + + Successful/unsuccessful uses of the chage command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the chcon command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the ssh-agent in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the passwd command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the umount command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the unix_update in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of postdrop in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of postqueue in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of semanage in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of setfiles in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of userhelper in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of setsebool in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of unix_chkpwd in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the ssh-keysign in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the setfacl command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the pam_timestamp_check command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the newgrp command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the init_module and finit_module system calls in the operating system must generate an audit record. + + + + + + + + + + + + Successful/unsuccessful uses of the gpasswd command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the delete_module command in the operating system must generate an audit record. + + + + + + + + + + Successful/unsuccessful uses of the crontab command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the chsh command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in the operating system must generate an audit record. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in the operating system must generate an audit record. + + + + + + + + + + + + + + + + Successful/unsuccessful uses of the sudo command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the usermod command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the chacl command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the kmod command in the operating system must generate an audit record. + + + + + + + + + The operating system must enable auditing of processes that start prior to the audit daemon. + + + + + + + + + + The operating system audit tools must be group-owned by root. + + + + + + + + + The operating system must have the packages required for offloading audit logs installed. + + + + + + + + + The operating system must have the packages required for encrypting offloaded audit logs installed. + + + + + + + + + The operating system must take appropriate action when the internal event queue is full. + + + + + + + + + The operating system must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. + + + + + + + + + + The operating system must not have the telnet-server package installed. + + + + + + + + + The operating system must enable mitigations against processor-based vulnerabilities. + + + + + + + + + + The operating system must be configured to disable USB mass storage. + + + + + + + + + + The operating system Bluetooth must be disabled. + + + + + + + + + + The operating system must mount /dev/shm with the nodev option. + + + + + + + + + + The operating system must mount /dev/shm with the nosuid option. + + + + + + + + + + The operating system must mount /dev/shm with the noexec option. + + + + + + + + + + The operating system must mount /tmp with the nodev option. + + + + + + + + + + + The operating system must mount /var/log/audit with the nodev option. + + + + + + + + + + + The operating system must mount /var/log/audit with the nosuid option. + + + + + + + + + + The operating system must mount /var/log/audit with the noexec option. + + + + + + + + + + The operating system must force a frequent session key renegotiation for SSH connections to the server. + + + + + + + + + + + + + The x86 Ctrl-Alt-Delete key sequence must be disabled on the operating system. + + + + + + + + + + The debug-shell systemd service must be disabled on the operating system. + + + + + + + + + + The root account must be the only account having unrestricted access to the operating system system. + + + + + + + + + The operating system must be configured to prevent unrestricted mail relaying. + + + + + + + + + The operating system operating system must log SSH connection attempts and failures to the server. + + + + + + + + + The systemd Ctrl-Alt-Delete burst key sequence in the operating system must be disabled. + + + + + + + + + The operating system must use the invoking user's password for privilege escalation when using "sudo". + + + + + + + + + + + + + + + + + + + The operating system must require re-authentication when using the "sudo" command. + + + + + + + + + The operating system must generate audit records for successful/unsuccessful uses of the sudoedit command. + + + + + + + + + The operating system pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication. + + + + + + + + + The operating system must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. + + + + + + + + + + The operating system must not allow blank or null passwords in the system-auth file. + + + + + + + + + The operating system must not allow blank or null passwords in the password-auth file. + + + + + + + + + The operating system must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. + + + + + + + + + The operating system fapolicy module must be enabled. + + + + + + + + + The operating system must enable kernel parameters to enforce discretionary access control on symlinks. + + + + + + + + + The operating system must enable kernel parameters to enforce discretionary access control on hardlinks. + + + + + + + + + The operating system must restrict access to the kernel message buffer. + + + + + + + + + The operating system must prevent kernel profiling by unprivileged users. + + + + + + + + + The operating system operating system must not have accounts configured with blank or null passwords. + + + + + + + + + The operating system must ensure the password complexity module is enabled in the system-auth file. + + + + + + + + + The graphical display manager must not be the default target on the operating system unless approved. + + + + + + + + + The operating system audit system must be configured to audit any usage of the "fsetxattr" system call. + + + + + + + + + + + + The operating system audit system must be configured to audit any usage of the "lsetxattr" system call. + + + + + + + + + + + + Successful/unsuccessful uses of the fremovexattr system call in the operating system must generate an audit record. + + + + + + + + + + + + Successful/unsuccessful uses of the "lremovexattr" system call in the operating system must generate an audit record. + + + + + + + + + + + + Successful/unsuccessful uses of the "removexattr" system call in the operating system must generate an audit record. + + + + + + + + + + + + The operating system SSH private host key files must have mode 0600 or less permissive. + + + + + + + + + The operating system systemd-journald service must be enabled. + + + + + + + + + The operating system must require a boot loader superuser password. + + + + + + + + + + The operating system must disable the ability of systemd to spawn an interactive boot process. + + + + + + + + + + The operating system /boot/grub2/grub.cfg file must be group-owned by root. + + + + + + + + + The operating system /boot/grub2/grub.cfg file must be owned by root. + + + + + + + + + The operating system must restrict exposed kernel pointer addresses access. + + + + + + + + + The operating system must disable the controller area network (CAN) protocol. + + + + + + + + + + The operating system must check the GPG signature of software packages originating from external software repositories before installation. + + + + + + + + + A File Transfer Protocol (FTP) server package must not be installed unless mission essential on the operating system. + + + + + + + + + The operating system must have the gnutls-utils package installed. + + + + + + + + + The operating system must prevent device files from being interpreted on file systems that contain user home directories. + + + + + + + + + The operating system must prevent code from being executed on file systems that contain user home directories. + + + + + + + + + The operating system must mount /boot with the nodev option. + + + + + + + + + The operating system /etc/group file must be group-owned by root. + + + + + + + + + The operating system /etc/group- file must be owned by root. + + + + + + + + + The operating system /etc/group- file must be group-owned by root. + + + + + + + + + The operating system /etc/gshadow file must be owned by root. + + + + + + + + + The operating system /etc/gshadow file must be group-owned by root. + + + + + + + + + The operating system /etc/gshadow- file must be owned by root. + + + + + + + + + The operating system /etc/gshadow- file must be group-owned by root. + + + + + + + + + The operating system /etc/passwd file must be owned by root. + + + + + + + + + The operating system /etc/passwd file must be group-owned by root. + + + + + + + + + The operating system /etc/passwd- file must be owned by root. + + + + + + + + + The operating system /etc/passwd- file must be group-owned by root. + + + + + + + + + The operating system /etc/shadow file must be owned by root. + + + + + + + + + The operating system /etc/shadow file must be group-owned by root. + + + + + + + + + The operating system /etc/shadow- file must be owned by root. + + + + + + + + + The operating system /etc/shadow- file must be group-owned by root. + + + + + + + + + The operating system libreswan package must be installed. + + + + + + + + + All the operating system networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. + + + + + + + + + The operating system must have the openssh-clients package installed. + + + + + + + + + The operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a ssh logon. + + + + + + + + + + The operating system must implement DOD-approved encryption ciphers to protect the confidentiality of SSH server connections. + + + + + + + + + The operating system SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms. + + + + + + + + + The operating system SSH daemon must be configured with a timeout interval. + + + + + + + + + The operating system must prevent a user from overriding the banner-message-enable setting for the graphical user interface. + + + + + + + + + + The operating system must disable the graphical user interface automount function unless required. + + + + + + + + + The operating system must prevent a user from overriding the session lock-delay setting for the graphical user interface. + + + + + + + + + + The operating system must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. + + + + + + + + + + The operating system must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. + + + + + + + + + The operating system must disable the user list at logon for graphical user interfaces. + + + + + + + + + The operating system user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs. + + + + + + + + + The operating system duplicate User IDs (UIDs) must not exist for interactive users. + + + + + + + + + The operating system system accounts must not have an interactive login shell. + + + + + + + + + All the operating system interactive users must have a primary group that exists. + + + + + + + + + All the operating system local interactive users must have a home directory assigned in the /etc/passwd file. + + + + + + + + + + The operating system groups must have unique Group ID (GID). + + + + + + + + + The operating system must automatically exit interactive command shell user sessions after 10 minutes of inactivity. + + + + + + + + + The operating system must define default permissions for the bash shell. + + + + + + + + + The operating system must define default permissions for the c shell. + + + + + + + + + The operating system must define default permissions for the system default profile. + + + + + + + + + The operating system must require users to reauthenticate for privilege escalation. + + + + + + + + + + The operating system must restrict privilege elevation to authorized personnel. + + + + + + + + + + The operating system must restrict the use of the "su" command. + + + + + + + + + Systems below version 8.4 must ensure the password complexity module in the system-auth file is configured for three retries or less. + + + + + + + + + The operating system password-auth must be configured to use a sufficient number of hashing rounds. + + + + + + + + + The operating system system-auth must be configured to use a sufficient number of hashing rounds. + + + + + + + + + The operating system must enforce password complexity rules for the root account. + + + + + + + + + The operating system operating system must not be configured to bypass password requirements for privilege escalation. + + + + + + + + + The operating system must use the CAC smart card driver. + + + + + + + + + The operating system must have the pcsc-lite package installed. + + + + + + + + + The pcscd service on the operating system must be active. + + + + + + + + + The operating system must have the opensc package installed. + + + + + + + + + The operating system operating system must use a file integrity tool to verify correct operation of all security functions. + + + + + + + + + + The rsyslog service must be running in the operating system. + + + + + + + + + The operating system must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. + + + + + + + + + All the operating system remote access methods must be monitored. + + + + + + + + + + + The operating system audit records must be off-loaded onto a different system or storage media from the system being audited. + + + + + + + + + + The operating system audit service must be enabled. + + + + + + + + + + The operating system must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility. + + + + + + + + + + The operating system must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. + + + + + + + + + The operating system must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. + + + + + + + + + The operating system must periodically flush audit records to disk to prevent the loss of audit records. + + + + + + + + + The operating system must write audit records to disk. + + + + + + + + + Successful/unsuccessful uses of the init command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the poweroff command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the reboot command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the shutdown command in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the umount system call in the operating system must generate an audit record. + + + + + + + + + Successful/unsuccessful uses of the umount2 system call in the operating system must generate an audit record. + + + + + + + + + + The operating system must take appropriate action when a critical audit processing failure occurs. + + + + + + + + + The operating system must enable FIPS mode. + + + + + + + + + The operating system IP tunnels must use FIPS 140-2/140-3 approved cryptographic algorithms. + + + + + + + + + + + + + The operating system must have the crypto-policies package installed. + + + + + + + + + The operating system must implement DOD-approved encryption in the bind package. + + + + + + + + + The operating system SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. + + + + + + + + + The operating system SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. + + + + + + + + + The operating system fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. + + + + + + + + + + The operating system must not allow users to override SSH environment variables. + + + + + + + + + The operating system must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. + + + + + + + + + The operating system must prevent the loading of a new kernel for later execution. + + + + + + + + + The operating system system commands must be owned by root. + + + + + + + + + The operating system must elevate the SELinux context when an administrator calls the sudo command. + + + + + + + + + The operating system must not have the "tftp" package installed. + + + + + + + + + The operating system must have the "pcsc-lite-ccid" package installed. + + + + + + + + + The operating system must use cryptographic mechanisms to protect the integrity of audit tools. + + + + + + + + + + + + + The operating system must have the "cronie" package installed. + + + + + + + + + The operating system must have the "pkcs11-provider" package installed. + + + + + + + + + The operating system audit tools must have a mode of 0755 or less permissive. + + + + + + + + + Successful/unsuccessful uses of the mount command in the operating system must generate an audit record. + + + + + + + + + + The operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. + + + + + + + + + + The operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. + + + + + + + + + + The operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. + + + + + + + + + + The operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd. + + + + + + + + + + The operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. + + + + + + + + + + The operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. + + + + + + + + + + The operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock. + + + + + + + + + + Successful/unsuccessful modifications to the lastlog file in the operating system must generate an audit record. + + + + + + + + + + The operating system must generate audit records for all uses of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls. + + + + + + + + + + + + + + + + The operating system must generate audit records for all uses of the "rename", "unlink", "rmdir", "renameat", "renameat2", and "unlinkat" system calls. + + + + + + + + + + + + + + + + + + + + The operating system must be a vendor-supported release. + + + + + + + + + The autofs package is installed. + + + + + + + + + The system has nfs entries in /etc/fstab + + + + + + + + + The postifx package is installed. + + + + + + + + + The Trivial File Transfer Protocol (TFTP) server package is installed. + + + + + + + + + The libreswan package is installed. + + + + + + + + + The system has BIND installed. + + + + + + + + + Gnome is installed + + Linux Systems + + + + + + + + + + + Linux United Extensible Firmware Interface (UEFI) + + Linux Systems + + + + + + + + + + IPv6 is disabled in the kernel. + + Linux Systems + + IPv6 is disabled in the kernel, either via a kernel cmdline option or sysctl. + + + + + + + + + + + + Linux UEFI Boot Partition Not VFAT File Type + + Linux Systems + + + + + + + + + + + + + + RHEL-10-700970 - RHEL 10 must disable the debug-shell systemd service. + + Red Hat Enterprise Linux 10 + + The debug-shell requires no authentication and provides root privileges to anyone who has physical access to the machine. While this feature is disabled by default, masking it adds an additional layer of assurance that it will not be enabled via a dependency in systemd. This also prevents attackers with physical access from trivially bypassing security on the machine through valid troubleshooting configurations and gaining root access when the system is rebooted. + + + + + + + + RHEL-10-001030 - RHEL 10 must check the GNU Privacy Guard (GPG) signature of software packages originating from external software repositories before installation. + + Red Hat Enterprise Linux 10 + + Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and has been provided by a trusted vendor. + + All software packages must be signed with a cryptographic key recognized and approved by the organization. + + Verifying the authenticity of software prior to installation validates the integrity of the software package received from a vendor. + + + + + + + + RHEL-10-001040 - RHEL 10 must check the GNU Privacy Guard (GPG) signature of locally installed software packages before installation. + + Red Hat Enterprise Linux 10 + + Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and that it has been provided by a trusted vendor. + + All software packages must be signed with a cryptographic key recognized and approved by the organization. + + Verifying the authenticity of software prior to installation validates the integrity of the software package received from a vendor. + + + + + + + + RHEL-10-001050 - RHEL 10 must have GNU Privacy Guard (GPG) signature verification enabled for all software repositories. + + Red Hat Enterprise Linux 10 + + Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and has been provided by a trusted vendor. + + All software packages must be signed with a cryptographic key recognized and approved by the organization. + + Verifying the authenticity of software prior to installation validates the integrity of the software package received from a vendor. + + + + + + + + RHEL-10-000530 - RHEL 10 must use a separate file system for user home directories (such as "/home" or an equivalent). + + Red Hat Enterprise Linux 10 + + Ensuring that "/home" is mounted on its own partition enables the setting of more restrictive mount options and helps ensure that users cannot trivially fill partitions used for log or audit data storage. + + + + + + + + RHEL-10-200020 - RHEL 10 must not have the "telnet-server" package installed. + + Red Hat Enterprise Linux 10 + + It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities are often overlooked and therefore, may remain unsecure. They increase the risk to the platform by providing additional attack vectors. + + The telnet service provides an unencrypted remote access service, which does not provide for the confidentiality and integrity of user passwords or the remote session. If a privileged user were to log in using this service, the privileged user password could be compromised. + + Removing the "telnet-server" package decreases the risk of accidental (or intentional) activation of the telnet service. + + + + + + + + RHEL-10-200070 - RHEL 10 must not have the "tftp" package installed. + + Red Hat Enterprise Linux 10 + + It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or mission objectives. These unnecessary capabilities are often overlooked and therefore, may remain unsecure. They increase the risk to the platform by providing additional attack vectors. + + If Trivial File Transfer Protocol (TFTP) is required for operational support (such as transmission of router configurations), its use must be documented with the information system security manager, restricted to only authorized personnel, and have access control rules established. + + + + + + + + RHEL-10-200090 - RHEL 10 must not have a File Transfer Protocol (FTP) server package installed. + + Red Hat Enterprise Linux 10 + + The FTP service provides an unencrypted remote access that does not provide for the confidentiality and integrity of user passwords or the remote session. If a privileged user were to log in using this service, the privileged user password could be compromised. Secure Shell (SSH) or other encrypted file transfer methods must be used in place of this service. + + Removing the "vsftpd" package decreases the risk of accidental activation. + + Satisfies: SRG-OS-000074-GPOS-00042, SRG-OS-000095-GPOS-00049 + + + + + + + + RHEL-10-200601 - RHEL 10 must enable the "fapolicy" module. + + Red Hat Enterprise Linux 10 + + The organization must identify authorized software programs and permit execution of authorized software. The process used to identify software programs that are authorized to execute on organizational information systems is commonly referred to as allowlisting. + + Using an allowlist provides a configuration management method for allowing the execution of only authorized software. Using only authorized software decreases risk by limiting the number of potential vulnerabilities. Verification of allowlisted software occurs prior to execution or at system startup. + + User home directories/folders may contain information of a sensitive nature. Nonprivileged users should coordinate any sharing of information with a system administrator through shared resources. + + RHEL 10 ships with many optional packages. One such package is a file access policy daemon called "fapolicyd". The "fapolicyd" is a userspace daemon that determines access rights to files based on attributes of the process and file. It can be used to either blocklist or allowlist processes or file access. + + Proceed with caution with enforcing the use of this daemon. Improper configuration may render the system nonfunctional. The "fapolicyd" application programming interface (API) is not namespace aware and can cause issues when launching or running containers. + + Satisfies: SRG-OS-000370-GPOS-00155, SRG-OS-000368-GPOS-00154 + + + + + + + + RHEL-10-200602 - RHEL 10 must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. + + Red Hat Enterprise Linux 10 + + The organization must identify authorized software programs and permit execution of authorized software. The process used to identify software programs that are authorized to execute on organizational information systems is commonly referred to as allowlisting. + + Using an allowlist provides a configuration management method for allowing the execution of only authorized software. Using only authorized software decreases risk by limiting the number of potential vulnerabilities. Verification of allowlisted software occurs prior to execution or at system startup. + + User home directories/folders may contain information of a sensitive nature. Nonprivileged users should coordinate any sharing of information with a system administrator through shared resources. + + RHEL 10 ships with many optional packages. One such package is a file access policy daemon called "fapolicyd". The "fapolicyd" is a userspace daemon that determines access rights to files based on attributes of the process and file. It can be used to either block list or allowlist processes or file access. + + Proceed with caution with enforcing the use of this daemon. Improper configuration may render the system nonfunctional. The "fapolicyd" application programming interface (API) is not namespace aware and can cause issues when launching or running containers. + + Satisfies: SRG-OS-000368-GPOS-00154, SRG-OS-000370-GPOS-00155 + + + + + + + + RHEL-10-200610 - RHEL 10 must have the "pcsc-lite" package installed. + + Red Hat Enterprise Linux 10 + + The "pcsc-lite" package must be installed if it is to be available for multifactor authentication using smart cards. + + + + + + + + RHEL-10-200611 - RHEL 10 must have the "pcscd" service set to active. + + Red Hat Enterprise Linux 10 + + The information system ensures that even if it is compromised, that compromise will not affect credentials stored on the authentication device. + + The daemon program for "pcsc-lite" and the MuscleCard framework is "pcscd". It is a resource manager that coordinates communications with smart card readers, smart cards, and cryptographic tokens that are connected to the system. + + + + + + + + RHEL-10-200612 - RHEL 10 must have the "pcsc-lite-ccid" package installed. + + Red Hat Enterprise Linux 10 + + The "pcsc-lite-ccid" package must be installed if it is to be available for multifactor authentication using smart cards. + + + + + + + + RHEL-10-200620 - RHEL 10 must have the "opensc" package installed. + + Red Hat Enterprise Linux 10 + + The use of Personal Identity Verification (PIV) credentials facilitates standardization and reduces the risk of unauthorized access. + + The DOD has mandated the use of the common access card (CAC) to support identity management and personal authentication for systems covered under Homeland Security Presidential Directive (HSPD) 12, as well as making the CAC a primary component of layered protection for national security systems. + + Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000376-GPOS-00161 + + + + + + + + RHEL-10-200621 - RHEL 10 must use the common access card (CAC) smart card driver. + + Red Hat Enterprise Linux 10 + + Smart card login provides two-factor authentication stronger than that provided by a username and password combination. Smart cards leverage public key infrastructure to provide and verify credentials. Configuring the smart card driver helps to prevent the use of unauthorized smart cards. + + Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000106-GPOS-00053, SRG-OS-000107-GPOS-00054, SRG-OS-000109-GPOS-00056, SRG-OS-000108-GPOS-00055 + + + + + + + + RHEL-10-200630 - RHEL 10 must have the Advanced Intrusion Detection Environment (AIDE) package installed. + + Red Hat Enterprise Linux 10 + + Without verification of the security functions, security functions may not operate correctly, and the failure may go unnoticed. Security function is defined as the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based. + + Security functionality includes, but is not limited to, establishing system accounts, configuring access authorizations (e.g., permissions, privileges), setting events to be audited, and setting intrusion detection parameters. + + + + + + + + RHEL-10-200631 - RHEL 10 must use cryptographic mechanisms to protect the integrity of audit tools. + + Red Hat Enterprise Linux 10 + + Protecting the integrity of the tools used for auditing purposes is a critical step toward ensuring the integrity of audit information. Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity. + + Audit tools include, but are not limited to, vendor-provided and open-source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators. + + It is not uncommon for attackers to replace the audit tools or inject code into the existing tools to provide the capability to hide or erase system activity from the audit logs. + + To address this risk, audit tools must be cryptographically signed to provide the capability to identify when the audit tools have been modified, manipulated, or replaced. An example is a checksum hash of the file or files. + + + + + + + + RHEL-10-200640 - RHEL 10 must have the "rsyslog" package installed. + + Red Hat Enterprise Linux 10 + + The "rsyslogd" is a system utility providing support for message logging. Support for both internet and Unix domain sockets enables this utility to support local and remote logging. Couple this utility with "gnutls" (which is a secure communications library implementing the Secure Sockets Layer [SSL], Transport Layer Security [TLS], and Datagram TLS [DTLS] protocols), to create a method to securely encrypt and off-load auditing. + + Satisfies: SRG-OS-000479-GPOS-00224, SRG-OS-000051-GPOS-00024 + + + + + + + + RHEL-10-200641 - RHEL 10 must have the rsyslog service set to active. + + Red Hat Enterprise Linux 10 + + The rsyslog service must be running to provide logging services, which are essential to system administration. + + + + + + + + RHEL-10-200642 - RHEL 10 must be configured to forward audit records via Transmission Control Protocol (TCP) to a different system or media from the system being audited via rsyslog. + + Red Hat Enterprise Linux 10 + + Information stored in one location is vulnerable to accidental or incidental deletion or alteration. + + Off-loading is a common process in information systems with limited audit storage capacity. + + RHEL 10 installation media provides "rsyslogd", a system utility providing support for message logging. Support for both internet and Unix domain sockets enables this utility to support both local and remote logging. Coupling this utility with "gnutls" (a secure communications library implementing the Secure Sockets Layer [SSL], Transport Layer Security [TLS], and Datagram TLS [DTLS] protocols) creates a method to securely encrypt and off-load auditing. + + The rsyslog provides three ways to forward message: the traditional User Datagram Protocol (UDP) transport, which is extremely lossy but standard; the plain TCP-based transport, which loses messages only during certain situations but is widely available; and the Reliable Event Logging Protocol (RELP) transport, which does not lose messages but is currently available only as part of the rsyslogd 3.15.0 and above. + + Examples of each configuration: + + UDP *.* @remotesystemname + TCP *.* @@remotesystemname + RELP *.* :omrelp:remotesystemname:2514 + + Note that a port number was given as there is no standard port for RELP. + + + + + + + + RHEL-10-200643 - RHEL 10 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. + + Red Hat Enterprise Linux 10 + + Unintentionally running a rsyslog server accepting remote messages puts the system at increased risk. Malicious rsyslog messages sent to the server could exploit vulnerabilities in the server software, introduce misleading information into the system's logs, or fill the system's storage, leading to a denial of service. + + If the system is intended to be a log aggregation server, its use must be documented with the information system security officer. + + + + + + + + RHEL-10-200647 - RHEL 10 must monitor all remote access methods. + + Red Hat Enterprise Linux 10 + + Logging remote access methods can be used to trace the decrease in the risks associated with remote user access management. It can also be used to spot cyberattacks and ensure ongoing compliance with organizational policies surrounding the use of remote access methods. + + + + + + + + RHEL-10-200650 - RHEL 10 must have the packages required for encrypting off-loaded audit logs installed. + + Red Hat Enterprise Linux 10 + + The "rsyslog-gnutls" package provides Transport Layer Security (TLS) support for the rsyslog daemon, which enables secure remote logging. + + + + + + + + RHEL-10-200660 - RHEL 10 must have the "audit" package installed. + + Red Hat Enterprise Linux 10 + + Without establishing what type of events occurred, along with the source, location, and outcome, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. + + Audit record content that may be necessary to satisfy this requirement includes, for example, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked. + + Associating event types with detected events in audit logs provides a means of investigating an attack, recognizing resource utilization or capacity thresholds, or identifying an improperly configured RHEL 10 system. + + Satisfies: SRG-OS-000062-GPOS-00031, SRG-OS-000037-GPOS-00015, SRG-OS-000038-GPOS-00016, SRG-OS-000039-GPOS-00017, SRG-OS-000040-GPOS-00018, SRG-OS-000041-GPOS-00019, SRG-OS-000042-GPOS-00021, SRG-OS-000051-GPOS-00024, SRG-OS-000054-GPOS-00025, SRG-OS-000122-GPOS-00063, SRG-OS-000254-GPOS-00095, SRG-OS-000255-GPOS-00096, SRG-OS-000337-GPOS-00129, SRG-OS-000348-GPOS-00136, SRG-OS-000349-GPOS-00137, SRG-OS-000350-GPOS-00138, SRG-OS-000351-GPOS-00139, SRG-OS-000352-GPOS-00140, SRG-OS-000353-GPOS-00141, SRG-OS-000354-GPOS-00142, SRG-OS-000358-GPOS-00145, SRG-OS-000365-GPOS-00152, SRG-OS-000392-GPOS-00172, SRG-OS-000475-GPOS-00220 + + + + + + + + RHEL-10-200661 - RHEL 10 must enable the audit service. + + Red Hat Enterprise Linux 10 + + Without establishing what type of events occurred, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. Ensuring the auditd service is active ensures audit records generated by the kernel are appropriately recorded. + + Additionally, a properly configured audit subsystem ensures that actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions. + + Satisfies: SRG-OS-000062-GPOS-00031, SRG-OS-000037-GPOS-00015, SRG-OS-000038-GPOS-00016, SRG-OS-000039-GPOS-00017, SRG-OS-000040-GPOS-00018, SRG-OS-000041-GPOS-00019, SRG-OS-000042-GPOS-00021, SRG-OS-000051-GPOS-00024, SRG-OS-000054-GPOS-00025, SRG-OS-000122-GPOS-00063, SRG-OS-000254-GPOS-00095, SRG-OS-000255-GPOS-00096, SRG-OS-000337-GPOS-00129, SRG-OS-000348-GPOS-00136, SRG-OS-000349-GPOS-00137, SRG-OS-000350-GPOS-00138, SRG-OS-000351-GPOS-00139, SRG-OS-000352-GPOS-00140, SRG-OS-000353-GPOS-00141, SRG-OS-000354-GPOS-00142, SRG-OS-000358-GPOS-00145, SRG-OS-000365-GPOS-00152, SRG-OS-000392-GPOS-00172, SRG-OS-000475-GPOS-00220 + + + + + + + + RHEL-10-200680 - RHEL 10 must have the "libreswan" package installed. + + Red Hat Enterprise Linux 10 + + Providing the ability for remote users or systems to initiate a secure virtual private network connection protects information when it is transmitted over a wide area network. + + + + + + + + RHEL-10-200692 - RHEL 10 must be configured to prevent unrestricted mail relaying. + + Red Hat Enterprise Linux 10 + + If unrestricted mail relaying is permitted, unauthorized senders could use this host as a mail relay to send spam or for other unauthorized activity. + + + + + + + + RHEL-10-200700 - RHEL 10 must have the "cronie" package installed. + + Red Hat Enterprise Linux 10 + + The "cronie" package must be installed if it is to be available for multifactor authentication using smart cards. + + + + + + + + RHEL-10-200721 - RHEL 10 must, for all networked systems, have and implement Secure Shell (SSH) to protect the confidentiality and integrity of transmitted and received information. + + Red Hat Enterprise Linux 10 + + Without protection of the transmitted information, confidentiality and integrity may be compromised because unprotected communications can be intercepted and either read or altered. + + This requirement applies to both internal and external networks and all types of information system components from which information can be transmitted (e.g., servers, mobile devices, notebook computers, printers, copiers, scanners, and facsimile machines). Communication paths outside the physical protection of a controlled boundary are exposed to the possibility of interception and modification. + + Protecting the confidentiality and integrity of organizational information can be accomplished by physical means (e.g., employing physical distribution systems) or logical means (e.g., employing cryptographic techniques). If physical means of protection are employed, then logical means (cryptography) do not have to be employed, and vice versa. + + Satisfies: SRG-OS-000423-GPOS-00187, SRG-OS-000424-GPOS-00188, SRG-OS-000425-GPOS-00189, SRG-OS-000426-GPOS-00190 + + + + + + + + RHEL-10-200722 - RHEL 10 must have the "openssh-clients" package installed. + + Red Hat Enterprise Linux 10 + + This package includes utilities to make encrypted connections and transfer files securely to Secure Shell (SSH) servers. + + + + + + + + RHEL-10-200730 - RHEL 10 must have the "pkcs11-provider" package installed. + + Red Hat Enterprise Linux 10 + + Without the use of multifactor authentication, the ease of access to privileged functions is greatly increased. Multifactor authentication requires using two or more factors to achieve authentication. A privileged account is defined as an information system account with authorizations of a privileged user. The DOD common access card (CAC) with DOD-approved PKI is an example of multifactor authentication. + + Satisfies: SRG-OS-000105-GPOS-00052, SRG-OS-000375-GPOS-00160, SRG-OS-000377-GPOS-00162 + + + + + + + + RHEL-10-200740 - RHEL 10 must have the "gnutls-utils" package installed. + + Red Hat Enterprise Linux 10 + + "GnuTLS" is a secure communications library implementing the Secure Sockets Layer (SSL), Transport Layer Security (TLS), and Datagram TLS (DTLS) protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP, and other required structures. This package contains command line TLS client and server and certificate manipulation tools. + + + + + + + + RHEL-10-300000 - RHEL 10 must have the "crypto-policies" package installed. + + Red Hat Enterprise Linux 10 + + Centralized cryptographic policies simplify applying secure ciphers across an operating system and the applications that run on that operating system. Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. + + Satisfies: SRG-OS-000396-GPOS-00176, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00174 + + + + + + + + RHEL-10-000500 - RHEL 10 must enable FIPS mode. + + Red Hat Enterprise Linux 10 + + Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. The operating system must implement cryptographic modules adhering to the higher standards approved by the federal government because this provides assurance they have been tested and validated. + + Satisfies: SRG-OS-000033-GPOS-00014, SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00174, SRG-OS-000396-GPOS-00176, SRG-OS-000423-GPOS-00187, SRG-OS-000478-GPOS-00223 + + + + + + + + RHEL-10-300030 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. + + Red Hat Enterprise Linux 10 + + Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + + Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganizational-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + + Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions that use asymmetric cryptography. This enables distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + + RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/openssh.config" file. + + Satisfies: SRG-OS-000033-GPOS-00014, SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00174, SRG-OS-000423-GPOS-00187 + + + + + + + + RHEL-10-300040 - RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. + + Red Hat Enterprise Linux 10 + + Without cryptographic integrity protections, unauthorized users can alter information without detection. + + Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganizational-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + + Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions that use asymmetric cryptography. This enables distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + + RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/opensshserver.config" file. + + Satisfies: SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093 + + + + + + + + RHEL-10-300050 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. + + Red Hat Enterprise Linux 10 + + Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + + Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganizational-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + + Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions that use asymmetric cryptography. This enables distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + + RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/openssh.config" file. + + Satisfies: SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093 + + + + + + + + RHEL-10-300060 - RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. + + Red Hat Enterprise Linux 10 + + Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + + Remote access (e.g., Remote Desktop Protocol [RDP]) is access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganization-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless. + + Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions using asymmetric cryptography enabling distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + + RHEL 10 incorporates systemwide crypto policies by default. The SSH configuration file has no effect on the ciphers, MACs, or algorithms unless specifically defined in the "/etc/sysconfig/sshd" file. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/opensshserver.config" file. + + Satisfies: SRG-OS-000125-GPOS-00065, SRG-OS-000250-GPOS-00093 + + + + + + + + RHEL-10-300070 - RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels. + + Red Hat Enterprise Linux 10 + + Overriding the systemwide cryptographic policy makes the behavior of the Libreswan service violate expectations and makes system configuration more fragmented. + + + + + + + + RHEL-10-300080 - RHEL 10 must implement DOD-approved encryption in the bind package. + + Red Hat Enterprise Linux 10 + + Without cryptographic integrity protections, information can be altered by unauthorized users without detection. + + Cryptographic mechanisms used for protecting the integrity of information include, for example, signed hash functions using asymmetric cryptography enabling distribution of the public key to verify the hash information while maintaining the confidentiality of the secret key used to generate the hash. + + RHEL 10 incorporates systemwide crypto policies by default. The employed algorithms can be viewed in the "/etc/crypto-policies/back-ends/" directory. + + Satisfies: SRG-OS-000423-GPOS-00187, SRG-OS-000426-GPOS-00190 + + + + + + + + RHEL-10-400005 - RHEL 10 must be configured so that the "/etc/group" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/group" file contains information regarding groups that are configured on the system. Protection of this file is important for system security. + + + + + + + + RHEL-10-400010 - RHEL 10 must be configured so that the "/etc/group-" file is owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/group-" file is a backup file of "/etc/group", and as such contains information regarding groups that are configured on the system. Protection of this file is important for system security. + + + + + + + + RHEL-10-400015 - RHEL 10 must be configured so that the "/etc/group-" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/group-" file is a backup file of "/etc/group", and as such contains information regarding groups that are configured on the system. Protection of this file is important for system security. + + + + + + + + RHEL-10-400020 - RHEL 10 must be configured so that the "/etc/gshadow" file is owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/gshadow" file contains group password hashes. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400025 - RHEL 10 must be configured so that the "/etc/gshadow" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/gshadow" file contains group password hashes. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400030 - RHEL 10 must be configured so that the "/etc/gshadow-" file is owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/gshadow-" file is a backup of "/etc/gshadow", and as such contains group password hashes. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400035 - RHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/gshadow-" file is a backup of "/etc/gshadow", and as such contains group password hashes. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400040 - RHEL 10 must be configured so that the "/etc/passwd" file is owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/passwd" file contains information about the users that are configured on the system. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400045 - RHEL 10 must be configured so that the "/etc/passwd" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/passwd" file contains information about the users that are configured on the system. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400050 - RHEL 10 must be configured so that the "/etc/passwd-" file is owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/passwd-" file is a backup file of "/etc/passwd", and as such contains information about the users that are configured on the system. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400055 - RHEL 10 must be configured so that the "/etc/passwd-" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/passwd-" file is a backup file of "/etc/passwd", and as such contains information about the users that are configured on the system. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400060 - RHEL 10 must be configured so that the "/etc/shadow" file is owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/shadow" file contains the list of local system accounts and stores password hashes. Protection of this file is critical for system security. Failure to give ownership of this file to "root" provides the designated owner with access to sensitive information, which could weaken the system security posture. + + + + + + + + RHEL-10-400065 - RHEL 10 must be configured so that the "/etc/shadow" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/shadow" file stores password hashes. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400070 - RHEL 10 must be configured so that the "/etc/shadow-" file is owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/shadow-" file is a backup file of "/etc/shadow", and as such contains the list of local system accounts and password hashes. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400075 - RHEL 10 must be configured so that the "/etc/shadow-" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + The "/etc/shadow-" file is a backup file of "/etc/shadow", and as such contains the list of local system accounts and password hashes. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400080 - RHEL 10 must be configured so that the "/var/log" directory is owned by "root". + + Red Hat Enterprise Linux 10 + + Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + + The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements. + + + + + + + + RHEL-10-400085 - RHEL 10 must be configured so that the "/var/log" directory is group-owned by "root". + + Red Hat Enterprise Linux 10 + + Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + + The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements. + + + + + + + + RHEL-10-400090 - RHEL 10 must be configured so that the "/var/log/"messages file is owned by root. + + Red Hat Enterprise Linux 10 + + Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + + The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements. + + + + + + + + RHEL-10-400095 - RHEL 10 must be configured so that the "/var/log/messages" file is group-owned by "root". + + Red Hat Enterprise Linux 10 + + Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can identify the RHEL 10 system or platform. Additionally, personally identifiable information (PII) and operational information must not be revealed through error messages to unauthorized personnel or their designated representatives. + + The structure and content of error messages must be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements. + + + + + + + + RHEL-10-400100 - RHEL 10 must be configured so that system commands are owned by "root". + + Red Hat Enterprise Linux 10 + + If RHEL 10 allowed any user to make changes to software libraries, those changes might be implemented without undergoing the appropriate testing and approvals that are part of a robust change management process. + + This requirement applies to RHEL 10 with software libraries that are accessible and configurable, as in the case of interpreted languages. Software libraries also include privileged programs that execute with escalated privileges. + + + + + + + + RHEL-10-400305 - RHEL 10 must be configured so that audit tools are group-owned by "root". + + Red Hat Enterprise Linux 10 + + Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data; therefore, protecting audit tools is necessary to prevent unauthorized operation on audit information. + + RHEL 10 systems providing tools to interface with audit information will leverage user permissions and roles identifying the user accessing the tools, and the corresponding rights the user enjoys, to make access decisions regarding the access to audit tools. + + Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators. + + Satisfies: SRG-OS-000256-GPOS-00097, SRG-OS-000257-GPOS-00098, SRG-OS-000258-GPOS-00099 + + + + + + + + RHEL-10-400315 - RHEL 10 must define default permissions for the bash shell. + + Red Hat Enterprise Linux 10 + + The "umask" controls the default access mode assigned to newly created files. A "umask" of "077" limits new files to mode "600" or less permissive. Although "umask" can be represented as a four-digit number, the first digit representing special access modes is typically ignored or required to be "0". + + This requirement applies to the globally configured system defaults and the local interactive user defaults for each account on the system. + + + + + + + + RHEL-10-400320 - RHEL 10 must define default permissions for the c shell. + + Red Hat Enterprise Linux 10 + + The "umask" controls the default access mode assigned to newly created files. A "umask" of "077" limits new files to mode "600" or less permissive. Although "umask" can be represented as a four-digit number, the first digit representing special access modes is typically ignored or required to be "0". + + This requirement applies to the globally configured system defaults and the local interactive user defaults for each account on the system. + + + + + + + + RHEL-10-400325 - RHEL 10 must define default permissions for all authenticated users in such a way that the user can read and modify only their own files. + + Red Hat Enterprise Linux 10 + + Setting the most restrictive default permissions ensures that when new accounts are created, they do not have unnecessary access. + + + + + + + + RHEL-10-400330 - RHEL 10 must define default permissions for the system default profile. + + Red Hat Enterprise Linux 10 + + The "umask" controls the default access mode assigned to newly created files. A "umask" of "077" limits new files to mode "600" or less permissive. "Although umask" can be represented as a four-digit number, the first digit representing special access modes is typically ignored or required to be "0". + + This requirement applies to the globally configured system defaults and the local interactive user defaults for each account on the system. + + + + + + + + RHEL-10-400340 - RHEL 10 must enforce mode "0600" or less permissive for Secure Shell (SSH) private host key files. + + Red Hat Enterprise Linux 10 + + If an unauthorized user obtains the private SSH host key file, the host could be impersonated. + + + + + + + + RHEL-10-400345 - RHEL 10 must enforce "root" group ownership of the "/boot/grub2/grub.cfg" file. + + Red Hat Enterprise Linux 10 + + The "root" group is a highly privileged group. Furthermore, the group owner of this file should not have any access privileges anyway. + + + + + + + + RHEL-10-400350 - RHEL 10 must enforce "root" ownership of the "/boot/grub2/grub.cfg" file. + + Red Hat Enterprise Linux 10 + + The " /boot/grub2/grub.cfg" file stores sensitive system configuration. Protection of this file is critical for system security. + + + + + + + + RHEL-10-400355 - RHEL 10 must prevent device files from being interpreted on file systems that contain user home directories. + + Red Hat Enterprise Linux 10 + + The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented. + + + + + + + + RHEL-10-400360 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories. + + Red Hat Enterprise Linux 10 + + The "nosuid" mount option causes the system to not execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-400365 - RHEL 10 must prevent code from being executed on file systems that contain user home directories. + + Red Hat Enterprise Linux 10 + + The "noexec" mount option causes the system to not execute binary files. This option must be used for mounting any file system not containing approved binary files, as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-400400 - RHEL 10 must mount "/var/log/audit" with the "nodev" option. + + Red Hat Enterprise Linux 10 + + The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented. + + + + + + + + RHEL-10-400405 - RHEL 10 must mount "/var/log/audit" with the "noexec" option. + + Red Hat Enterprise Linux 10 + + The "noexec" mount option causes the system to not execute binary files. This option must be used for mounting any file system not containing approved binary files, as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-400410 - RHEL 10 must mount "/var/log/audit" with the "nosuid" option. + + Red Hat Enterprise Linux 10 + + The "nosuid" mount option causes the system to not execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-400450 - RHEL 10 must enforce a mode of "0755" or less permissive for audit tools. + + Red Hat Enterprise Linux 10 + + Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is necessary to prevent unauthorized operation on audit information. + + RHEL 10 systems providing tools to interface with audit information will leverage user permissions and roles identifying the user accessing the tools, and the corresponding rights the user enjoys, to make access decisions regarding the access to audit tools. + + Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators. + + Satisfies: SRG-OS-000256-GPOS-00097, SRG-OS-000257-GPOS-00098, SRG-OS-000258-GPOS-00099 + + + + + + + + RHEL-10-500000 - RHEL 10 must enable the systemd-journald service. + + Red Hat Enterprise Linux 10 + + In the event of a system failure, RHEL 10 must preserve any information necessary to determine cause of failure and return to operations with least disruption to system processes. + + + + + + + + RHEL-10-500005 - RHEL 10 must enable auditing of processes that start prior to the audit daemon. + + Red Hat Enterprise Linux 10 + + Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + If auditing is enabled late in the startup process, the actions of some startup processes may not be audited. Some audit systems also maintain state information available only if auditing is enabled before a given process is created. + + + + + + + + RHEL-10-500010 - RHEL 10 must audit local events. + + Red Hat Enterprise Linux 10 + + Without establishing what type of events occurred, along with the source, location, and outcome, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. + + If option "local_events" is not set to "yes", only events from the network will be aggregated. + + + + + + + + RHEL-10-500015 - RHEL 10 must write audit records to disk. + + Red Hat Enterprise Linux 10 + + Audit data must be synchronously written to disk to ensure log integrity. This setting ensures that all audit event data is written to disk. + + + + + + + + RHEL-10-500020 - RHEL 10 must log username information when unsuccessful login attempts occur. + + Red Hat Enterprise Linux 10 + + Without auditing of these events, it may be harder or impossible to identify what an attacker did after an attack. + + + + + + + + RHEL-10-500035 - RHEL 10 must take appropriate action when a critical audit processing failure occurs. + + Red Hat Enterprise Linux 10 + + It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without this notification, the security personnel may be unaware of an impending failure of the audit capability, and system operation may be adversely affected. + + Audit processing failures include software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. + + + + + + + + RHEL-10-500040 - RHEL 10 must take action when allocated audit record storage volume reaches 75 percent of the audit record storage capacity. + + Red Hat Enterprise Linux 10 + + If action is not taken when storage volume reaches 75 percent utilization, the auditing system may fail when the storage volume reaches capacity. + + + + + + + + RHEL-10-500045 - RHEL 10 must label all off-loaded audit logs before sending them to the central log server. + + Red Hat Enterprise Linux 10 + + Enriched logging is needed to determine who, what, and when events occur on a system. Without this, determining root cause of an event will be much more difficult. + + When audit logs are not labeled before they are sent to a central log server, the audit data will not be able to be analyzed and tied back to the correct system. + + Satisfies: SRG-OS-000039-GPOS-00017, SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224 + + + + + + + + RHEL-10-500100 - RHEL 10 must allocate audit record storage capacity to store at least one week's worth of audit records. + + Red Hat Enterprise Linux 10 + + To ensure RHEL 10 systems have a sufficient storage capacity in which to write the audit logs, RHEL 10 must be able to allocate audit record storage capacity. + + The task of allocating audit record storage capacity is usually performed during initial installation of RHEL 10. + + Satisfies: SRG-OS-000341-GPOS-00132, SRG-OS-000342-GPOS-00133 + + + + + + + + RHEL-10-500105 - RHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. + + Red Hat Enterprise Linux 10 + + If action is not taken when storage volume reaches 95 percent utilization, the auditing system may fail when the storage volume reaches capacity. + + + + + + + + RHEL-10-500110 - RHEL 10 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. + + Red Hat Enterprise Linux 10 + + If action is not taken when storage volume reaches 95 percent utilization, the auditing system may fail when the storage volume reaches capacity. + + + + + + + + RHEL-10-500115 - RHEL 10 must take appropriate action when the internal event queue is full. + + Red Hat Enterprise Linux 10 + + The audit system must have an action set up in case the internal event queue becomes full so that no data is lost. Information stored in one location is vulnerable to accidental or incidental deletion or alteration. + + Off-loading is a common process in information systems with limited audit storage capacity. + + Satisfies: SRG-OS-000342-GPOS-00133, SRG-OS-000479-GPOS-00224 + + + + + + + + RHEL-10-500120 - RHEL 10 must produce audit records containing information to establish the identity of any individual or process associated with the event. + + Red Hat Enterprise Linux 10 + + Without establishing what type of events occurred, along with the source, location, and outcome, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. + + Audit record content that may be necessary to satisfy this requirement includes, for example, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked. + + Enriched logging aids in making sense of who, what, and when events occur on a system. Without this, determining root cause of an event will be much more difficult. + + + + + + + + RHEL-10-500125 - RHEL 10 must periodically flush audit records to disk to ensure that audit records are not lost. + + Red Hat Enterprise Linux 10 + + If option "freq" is not set to a value that requires audit records to be written to disk after a threshold number is reached, audit records may be lost. + + + + + + + + RHEL-10-500205 - RHEL 10 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization. + + Red Hat Enterprise Linux 10 + + If security personnel are not notified immediately when storage volume reaches 75 percent utilization, they are unable to plan for audit record storage capacity expansion. + + + + + + + + RHEL-10-500210 - RHEL 10 must notify the system administrator (SA) and/or information system security officer (ISSO) (at a minimum) of an audit processing failure. + + Red Hat Enterprise Linux 10 + + It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without this notification, the security personnel may be unaware of an impending failure of the audit capability, and system operation may be adversely affected. + + Audit processing failures include software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. + + This requirement applies to each audit data storage repository (i.e., distinct information system component where audit records are stored), the centralized audit storage capacity of organizations (i.e., all audit data storage repositories combined), or both. + + Satisfies: SRG-OS-000046-GPOS-00022, SRG-OS-000343-GPOS-00134 + + + + + + + + RHEL-10-500215 - RHEL 10 must log Secure Shell (SSH) connection attempts and failures to the server. + + Red Hat Enterprise Linux 10 + + SSH provides several logging levels with varying amounts of verbosity. "DEBUG" is specifically not recommended other than strictly for debugging SSH communications because it provides so much data that it is difficult to identify important security information. "INFO" or "VERBOSE" level is the basic level that only records login activity of SSH users. In many situations, such as incident response, it is important to determine when a particular user was active on a system. The logout record can eliminate users who disconnected, which helps narrow the field. + + + + + + + + RHEL-10-500300 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "execve" system call. + + Red Hat Enterprise Linux 10 + + Misuse of privileged functions, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromised information system accounts, is a serious and ongoing concern and can have significant adverse impacts on organizations. + + Auditing the use of privileged functions is one way to detect such misuse and identify the risk from insider threats and the advanced persistent threat. + + Satisfies: SRG-OS-000326-GPOS-00126, SRG-OS-000327-GPOS-00127, SRG-OS-000755-GPOS-00220 + + + + + + + + RHEL-10-500310 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "setxattr", "fsetxattr", "lsetxattr", "removexattr", "fremovexattr", and "lremovexattr" system calls. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000458-GPOS-00203, SRG-OS-000462-GPOS-00206, SRG-OS-000463-GPOS-00207, SRG-OS-000471-GPOS-00215, SRG-OS-000474-GPOS-00219, SRG-OS-000466-GPOS-00210, SRG-OS-000468-GPOS-00212, SRG-OS-000064-GPOS-00033 + + + + + + + + RHEL-10-500320 - RHEL 10 must generate audit records for successful and unsuccessful uses of "umount" system calls. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500330 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chacl" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210 + + + + + + + + RHEL-10-500340 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfacl" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500350 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chcon" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000468-GPOS-00212, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209 + + + + + + + + RHEL-10-500360 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "semanage" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209 + + + + + + + + RHEL-10-500370 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfiles" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209 + + + + + + + + RHEL-10-500380 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "setsebool" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209 + + + + + + + + RHEL-10-500390 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000064-GPOS-00033, SRG-OS-000458-GPOS-00203, SRG-OS-000461-GPOS-00205 + + + + + + + + RHEL-10-500400 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "delete_module" system call. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000471-GPOS-00216, SRG-OS-000477-GPOS-00222 + + + + + + + + RHEL-10-500410 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "init_module" and "finit_module" system calls. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000471-GPOS-00216, SRG-OS-000477-GPOS-00222 + + + + + + + + RHEL-10-500420 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chage" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000468-GPOS-00212, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500430 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chsh" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500440 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "crontab" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500450 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "gpasswd" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500460 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "kmod" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000471-GPOS-00216, SRG-OS-000477-GPOS-00222 + + + + + + + + RHEL-10-500470 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "newgrp" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500480 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "pam_timestamp_check" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500490 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "passwd" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500500 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "postdrop" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500510 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "postqueue" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500520 - RHEL 10 must generate audit records for successful and unsuccessful uses of the ssh-agent command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500530 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "ssh-keysign" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500540 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "su" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000064-GPOS-00033, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210, SRG-OS-000755-GPOS-00220 + + + + + + + + RHEL-10-500550 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "sudo" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210, SRG-OS-000755-GPOS-00220 + + + + + + + + RHEL-10-500560 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "sudoedit" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000755-GPOS-00220 + + + + + + + + RHEL-10-500570 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_chkpwd" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500580 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_update" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000064-GPOS-00033, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500590 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "userhelper" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500600 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "usermod" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each system call made by all programs on the system. Therefore, it is very important to use system call rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining system calls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210 + + + + + + + + RHEL-10-500610 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "mount" command. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500620 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "init" command. + + Red Hat Enterprise Linux 10 + + Misuse of the "init" command may cause availability issues for the system. + + + + + + + + RHEL-10-500630 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "poweroff" command. + + Red Hat Enterprise Linux 10 + + Misuse of the "poweroff" command may cause availability issues for the system. + + + + + + + + RHEL-10-500640 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "reboot" command. + + Red Hat Enterprise Linux 10 + + Misuse of the "reboot" command may cause system availability issues. + + + + + + + + RHEL-10-500650 - RHEL 10 must generate audit records for successful and unsuccessful uses of the shutdown command. + + Red Hat Enterprise Linux 10 + + Misuse of the shutdown command may cause availability issues for the system. + + + + + + + + RHEL-10-500660 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "umount" system call. + + Red Hat Enterprise Linux 10 + + The changing of file permissions could indicate that a user is attempting to gain access to information that would otherwise be disallowed. Auditing discretionary access control (DAC) modifications can facilitate the identification of patterns of abuse among both authorized and unauthorized users. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500670 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "umount2" system call. + + Red Hat Enterprise Linux 10 + + The changing of file permissions could indicate that a user is attempting to gain access to information that would otherwise be disallowed. Auditing discretionary access control (DAC) modifications can facilitate the identification of patterns of abuse among both authorized and unauthorized users. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215 + + + + + + + + RHEL-10-500680 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers". + + Red Hat Enterprise Linux 10 + + The actions taken by system administrators must be audited to keep a record of what was executed on the system, as well as for accountability purposes. Editing the "sudoers" file may be sign of an attacker trying to establish persistent methods to a system. Auditing the editing of the "sudoers" files mitigates this risk. + + Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221 + + + + + + + + RHEL-10-500700 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/group". + + Red Hat Enterprise Linux 10 + + In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications must be investigated for legitimacy. + + Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221 + + + + + + + + RHEL-10-500710 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/gshadow". + + Red Hat Enterprise Linux 10 + + In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + + Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221 + + + + + + + + RHEL-10-500720 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/opasswd". + + Red Hat Enterprise Linux 10 + + In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + + Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221 + + + + + + + + RHEL-10-500730 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/passwd". + + Red Hat Enterprise Linux 10 + + In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + + Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221, SRG-OS-000274-GPOS-00104, SRG-OS-000275-GPOS-00105, SRG-OS-000276-GPOS-00106, SRG-OS-000277-GPOS-00107 + + + + + + + + RHEL-10-500740 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow". + + Red Hat Enterprise Linux 10 + + In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy. + + Satisfies: SRG-OS-000004-GPOS-00004, SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000304-GPOS-00121, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000466-GPOS-00210, SRG-OS-000476-GPOS-00221 + + + + + + + + RHEL-10-500750 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/faillock". + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Satisfies: SRG-OS-000392-GPOS-00172, SRG-OS-000470-GPOS-00214, SRG-OS-000473-GPOS-00218 + + + + + + + + RHEL-10-500760 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/lastlog". + + Red Hat Enterprise Linux 10 + + Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000473-GPOS-00218, SRG-OS-000470-GPOS-00214 + + + + + + + + RHEL-10-500780 - RHEL 10 must generate audit records for all uses of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000064-GPOS-00033, SRG-OS-000466-GPOS-00210, SRG-OS-000458-GPOS-00203 + + + + + + + + RHEL-10-500790 - RHEL 10 must generate audit records for all uses of the "chown", "fchown", "fchownat", and "lchown" syscalls. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000064-GPOS-00033, SRG-OS-000466-GPOS-00210, SRG-OS-000458-GPOS-00203, SRG-OS-000474-GPOS-00219 + + + + + + + + RHEL-10-500810 - RHEL 10 must generate audit records for all uses of the "rename", "unlink", "rmdir", "renameat", "renameat2", and "unlinkat" system calls. + + Red Hat Enterprise Linux 10 + + Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. + + Audit records can be generated from various components within the information system (e.g., module or policy filter). + + When a user logs on, the auid is set to the uid of the account that is being authenticated. Daemons are not user sessions and have the loginuid set to -1. The auid representation is an unsigned 32-bit integer, which equals 4294967295. The audit system interprets -1, 4294967295, and "unset" in the same way. + + The system call rules are loaded into a matching engine that intercepts each syscall made by all programs on the system. Therefore, it is very important to use syscall rules only when absolutely necessary because these affect performance. More rules lead to poorer performance. The performance can be helped, however, by combining syscalls into one rule whenever possible. + + Satisfies: SRG-OS-000037-GPOS-00015, SRG-OS-000042-GPOS-00020, SRG-OS-000062-GPOS-00031, SRG-OS-000392-GPOS-00172, SRG-OS-000462-GPOS-00206, SRG-OS-000471-GPOS-00215, SRG-OS-000466-GPOS-00210, SRG-OS-000467-GPOS-00211, SRG-OS-000468-GPOS-00212 + + + + + + + + RHEL-10-600000 - RHEL 10 must require a boot loader superuser password. + + Red Hat Enterprise Linux 10 + + To mitigate the risk of unauthorized access to sensitive information by entities that have been issued certificates by DOD-approved PKIs, all DOD systems (e.g., web servers and web portals) must be properly configured to incorporate access control methods that do not rely solely on the possession of a certificate for access. + + Successful authentication must not automatically give an entity access to an asset or security boundary. Authorization procedures and controls must be implemented to ensure each authenticated entity also has a validated and current authorization. Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Information systems use access control policies and enforcement mechanisms to implement this requirement. + + Password protection on the boot loader configuration ensures users with physical access cannot trivially alter important bootloader settings. These include which kernel to use and whether to enter single-user mode. + + + + + + + + RHEL-10-600020 - RHEL 10 must not assign an interactive login shell for system accounts. + + Red Hat Enterprise Linux 10 + + Ensuring shells are not given to system accounts upon login makes it more difficult for attackers to use system accounts. + + + + + + + + RHEL-10-600100 - RHEL 10 must, for new users or password changes, have a 60-day maximum password lifetime restriction for user account passwords in "/etc/login.defs". + + Red Hat Enterprise Linux 10 + + Any password, no matter how complex, can eventually be cracked; therefore, passwords must be changed periodically. If the operating system does not limit the lifetime of passwords and force users to change their passwords, there is the risk that the operating system passwords could be compromised. + + Setting the password maximum age ensures users are required to periodically change their passwords. Requiring shorter password lifetimes increases the risk of users writing down the password in a convenient location subject to physical compromise. + + + + + + + + RHEL-10-600120 - RHEL 10 must assign a home directory for local interactive user accounts upon creation. + + Red Hat Enterprise Linux 10 + + If local interactive users are not assigned a valid home directory, there is no place for the storage and control of files they should own. + + + + + + + + RHEL-10-600130 - RHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users. + + Red Hat Enterprise Linux 10 + + To ensure accountability and prevent unauthenticated access, interactive users must be identified and authenticated to prevent potential misuse and compromise of the system. + + Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000121-GPOS-00062 + + + + + + + + RHEL-10-600150 - RHEL 10 must assign a primary group to all interactive users. + + Red Hat Enterprise Linux 10 + + If a user is assigned the group identifier (GID) of a group that does not exist on the system, and a group with the GID is subsequently created, the user may have unintended rights to any files associated with the group. + + + + + + + + RHEL-10-600160 - RHEL 10 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. + + Red Hat Enterprise Linux 10 + + Inactive identifiers pose a risk to systems and applications because attackers may exploit an inactive identifier and potentially obtain undetected access to the system. + + Disabling inactive accounts ensures accounts that may not have been responsibly removed are not available to attackers who may have compromised their credentials. + + Owners of inactive accounts will not notice if unauthorized access to their user account has been obtained. + + Satisfies: SRG-OS-000118-GPOS-00060, SRG-OS-000590-GPOS-00110 + + + + + + + + RHEL-10-600180 - RHEL 10 must assign a home directory to all local interactive users in the "/etc/passwd" file. + + Red Hat Enterprise Linux 10 + + If local interactive users are not assigned a valid home directory, there is no place for the storage and control of files they should own. + + + + + + + + RHEL-10-600200 - RHEL 10 must enforce a delay of at least four seconds between login prompts following a failed login attempt. + + Red Hat Enterprise Linux 10 + + Increasing the time between a failed authentication attempt and reprompting to enter credentials helps to slow a single-threaded brute-force attack. + + + + + + + + RHEL-10-600220 - RHEL 10 must enforce that passwords be created with a minimum of 15 characters. + + Red Hat Enterprise Linux 10 + + The shorter the password, the lower the number of possible combinations that must be tested before the password is compromised. + + Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password. Use of more characters in a password helps to increase exponentially the time and/or resources required to compromise the password. + + RHEL 10 uses "pwquality" as a mechanism to enforce password complexity. Configurations are set in the "etc/security/pwquality.conf" file. + + The "minlen", sometimes noted as minimum length, acts as a "score" of complexity based on the credit components of the "pwquality" module. By setting the credit components to a negative value, those components will not only be required but will not count toward the total "score" of "minlen". This will enable "minlen" to require a 15-character minimum. + + The DOD minimum password requirement is 15 characters. + + + + + + + + RHEL-10-600230 - RHEL 10 must enforce password complexity by requiring at least one special character to be used. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + + RHEL 10 uses "pwquality" as a mechanism to enforce password complexity. Note that to require special characters without degrading the "minlen" value, the credit value must be expressed as a negative number in "/etc/security/pwquality.conf". + + + + + + + + RHEL-10-600240 - RHEL 10 must enforce password complexity by requiring that at least one lowercase character be used. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + + Requiring a minimum number of lowercase characters makes password guessing attacks more difficult by ensuring a larger search space. + + + + + + + + RHEL-10-600250 - RHEL 10 must enforce password complexity by requiring that at least one uppercase character be used. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + + Requiring a minimum number of uppercase characters makes password guessing attacks more difficult by ensuring a larger search space. + + Satisfies: SRG-OS-000069-GPOS-00037, SRG-OS-000070-GPOS-00038 + + + + + + + + RHEL-10-600260 - RHEL 10 must require the change of at least eight characters when passwords are changed. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute–force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + + Requiring a minimum number of different characters during password changes ensures that newly changed passwords should not resemble previously compromised ones. + + Note that passwords that are changed on compromised systems will still be compromised. + + + + + + + + RHEL-10-600280 - RHEL 10 must require the maximum number of repeating characters of the same character class to be limited to four when passwords are changed. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. + + Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex a password is, the greater the number of possible combinations that must be tested before the password is compromised. + + Satisfies: SRG-OS-000072-GPOS-00040, SRG-OS-000730-GPOS-00190 + + + + + + + + RHEL-10-600290 - RHEL 10 must require that the maximum number of repeating characters be limited to three when passwords are changed. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. + + Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex a password is, the greater the number of possible combinations that must be tested before the password is compromised. + + + + + + + + RHEL-10-600300 - RHEL 10 must require the change of at least four character classes when passwords are changed. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. + + Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex a password is, the greater the number of possible combinations that must be tested before the password is compromised. + + + + + + + + RHEL-10-600310 - RHEL 10 must enforce password complexity by requiring that at least one numeric character be used. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password is, the greater the number of possible combinations that must be tested before the password is compromised. + + Requiring digits makes password guessing attacks more difficult by ensuring a larger search space. + + + + + + + + RHEL-10-600320 - RHEL 10 must prevent the use of dictionary words for passwords. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + If RHEL 10 allows the user to select passwords based on dictionary words, this increases the chances of password compromise by increasing the opportunity for successful guesses and brute-force attacks. + + Satisfies: SRG-OS-000480-GPOS-00225, SRG-OS-000072-GPOS-00040 + + + + + + + + RHEL-10-600400 - RHEL 10 must allow only the root account to have unrestricted access to the system. + + Red Hat Enterprise Linux 10 + + An account has root authority if it has a user identifier (UID) of "0". Multiple accounts with a UID of "0" afford more opportunity for potential intruders to guess a password for a privileged account. Proper configuration of sudo is recommended to afford multiple system administrators access to root privileges in an accountable manner. + + + + + + + + RHEL-10-600405 - RHEL 10 must enforce password complexity rules for the "root" account. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. + + Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that must be tested before the password is compromised. + + Satisfies: SRG-OS-000072-GPOS-00040, SRG-OS-000071-GPOS-00039, SRG-OS-000070-GPOS-00038, SRG-OS-000266-GPOS-00101, SRG-OS-000078-GPOS-00046, SRG-OS-000480-GPOS-00225, SRG-OS-000069-GPOS-00037 + + + + + + + + RHEL-10-600410 - RHEL 10 must automatically lock an account when three unsuccessful login attempts occur. + + Red Hat Enterprise Linux 10 + + By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-force attacks, is reduced. Limits are imposed by locking the account. + + Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005 + + + + + + + + RHEL-10-600415 - RHEL 10 must automatically lock the root account until the root account is released by an administrator when three unsuccessful login attempts occur during a 15-minute time period. + + Red Hat Enterprise Linux 10 + + By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, also known as brute-forcing, is reduced. Limits are imposed by locking the account. + + Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005 + + + + + + + + RHEL-10-600420 - RHEL 10 must automatically lock an account when three unsuccessful login attempts occur during a 15-minute time period. + + Red Hat Enterprise Linux 10 + + By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. Limits are imposed by locking the account. + + Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005 + + + + + + + + RHEL-10-600425 - RHEL 10 must maintain an account lock until the locked account is released by an administrator. + + Red Hat Enterprise Linux 10 + + By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. Limits are imposed by locking the account. + + Satisfies: SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005 + + + + + + + + RHEL-10-600430 - RHEL 10 must ensure account lockouts persist. + + Red Hat Enterprise Linux 10 + + Having lockouts persist across reboots ensures that an account is unlocked only by an administrator. If the lockouts did not persist across reboots, an attacker could reboot the system to continue brute force attacks against the accounts on the system. + + Satisfies: SRG-OS-000021-GPOS-00005, SRG-OS-000329-GPOS-00128 + + + + + + + + RHEL-10-600455 - RHEL 10 must not allow blank or null passwords. + + Red Hat Enterprise Linux 10 + + If an account has an empty password, anyone could log in and run commands with the privileges of that account. Accounts with empty passwords must never be used in operational environments. + + + + + + + + + RHEL-10-600460 - RHEL 10 must not have accounts configured with blank or null passwords. + + Red Hat Enterprise Linux 10 + + If an account has an empty password, anyone could log in and run commands with the privileges of that account. Accounts with empty passwords should never be used in operational environments. + + + + + + + + RHEL-10-600470 - RHEL 10 must have a unique group ID (GID) for each group in "/etc/group". + + Red Hat Enterprise Linux 10 + + To ensure accountability and prevent unauthenticated access, groups must be identified uniquely to prevent potential misuse and compromise of the system. + + + + + + + + RHEL-10-600485 - RHEL 10 must ensure the password complexity module in the system-auth file is configured for three or fewer retries. + + Red Hat Enterprise Linux 10 + + Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. "pwquality" enforces complex password construction configuration and has the ability to limit brute-force attacks on the system. + + RHEL 10 uses "pwquality" as a mechanism to enforce password complexity. This is set in both of the following: + + "/etc/pam.d/password-auth" + "/etc/pam.d/system-auth" + + By limiting the number of attempts to meet the pwquality module complexity requirements before returning with an error, the system will audit abnormal attempts at password changes. + + + + + + + + RHEL-10-600500 - RHEL 10 must restrict the use of the "su" command. + + Red Hat Enterprise Linux 10 + + The "su" program allows commands to be run with a substitute user and group ID. It is commonly used to run commands as the root user. Limiting access to such commands is considered a good security practice. + + Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000312-GPOS-00123 + + + + + + + + RHEL-10-600510 - RHEL 10 must be configured to not bypass password requirements for privilege escalation. + + Red Hat Enterprise Linux 10 + + Without reauthentication, users may access resources or perform tasks for which they do not have authorization. When operating systems provide the capability to escalate a functional capability, it is critical the user reauthenticate. + + Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158 + + + + + + + + RHEL-10-600520 - RHEL 10 must restrict privilege elevation to authorized personnel. + + Red Hat Enterprise Linux 10 + + If the "sudoers" file is not configured correctly, any user defined on the system can initiate privileged actions on the target system. + + + + + + + + RHEL-10-600530 - RHEL 10 must require users to reauthenticate for privilege escalation. + + Red Hat Enterprise Linux 10 + + Without reauthentication, users may access resources or perform tasks for which they do not have authorization. + + When operating systems provide the capability to escalate a functional capability, it is critical that the user reauthenticate. + + Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158 + + + + + + + + RHEL-10-600540 - RHEL 10 must require reauthentication when using the "sudo" command. + + Red Hat Enterprise Linux 10 + + Without reauthentication, users may access resources or perform tasks for which they do not have authorization. + + When operating systems provide the capability to escalate a functional capability, it is critical that the organization requires the user to reauthenticate when using the "sudo" command. + + If the value is set to an integer less than "0", the user's time stamp will not expire, and the user will not have to reauthenticate for privileged actions until the user's session is terminated. + + Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158 + + + + + + + + RHEL-10-600550 - RHEL 10 must use the invoking user's password for privilege escalation when using "sudo". + + Red Hat Enterprise Linux 10 + + If the "rootpw", "targetpw", or "runaspw" flags are defined and not disabled, by default the operating system will prompt the invoking user for the "root" user password. + + + + + + + + RHEL-10-600560 - RHEL 10 must require users to provide a password for privilege escalation. + + Red Hat Enterprise Linux 10 + + Without reauthentication, users may access resources or perform tasks for which they do not have authorization. + + When operating systems provide the capability to escalate a functional capability, it is critical that the user reauthenticate. + + Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158 + + + + + + + + RHEL-10-600620 - RHEL 10 must ensure the password complexity module is enabled in the "password-auth" file. + + Red Hat Enterprise Linux 10 + + Enabling Pluggable Authentication Module (PAM) password complexity permits enforcement of strong passwords and consequently makes the system less prone to dictionary attacks. + + Satisfies: SRG-OS-000069-GPOS-00037, SRG-OS-000070-GPOS-00038 + + + + + + + + RHEL-10-600630 - RHEL 10 must ensure the password complexity module is enabled in the "system-auth" file. + + Red Hat Enterprise Linux 10 + + Enabling Pluggable Authentication Module (PAM) password complexity permits enforcement of strong passwords and consequently makes the system less prone to dictionary attacks. + + + + + + + + RHEL-10-600650 - RHEL 10 must ensure that the pam_unix.so module is configured in the password-auth file to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication. + + Red Hat Enterprise Linux 10 + + Unapproved mechanisms that are used for authentication to the cryptographic module are not verified; therefore, they cannot be relied on to provide confidentiality or integrity, and DOD data may be compromised. + + RHEL 10 systems using encryption are required to use FIPS-compliant mechanisms for authenticating to cryptographic modules. + + FIPS 140-3 is the current standard for validating that mechanisms used to access cryptographic modules use authentication that meets DOD requirements. This allows for Security Levels 1, 2, 3, or 4 for use on a general-purpose computing system. + + Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061 + + + + + + + + RHEL-10-600700 - RHEL 10 must be configured to use a sufficient number of hashing rounds for the shadow password suite. + + Red Hat Enterprise Linux 10 + + Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + + Using more hashing rounds makes password cracking attacks more difficult. + + Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061 + + + + + + + + RHEL-10-600710 - RHEL 10 must be configured to use a FIPS 140-3-approved cryptographic hashing algorithm for system authentication by ensuring that the pam_unix.so module is configured in the "system-auth" file. + + Red Hat Enterprise Linux 10 + + Unapproved mechanisms that are used for authentication to the cryptographic module are not verified and therefore cannot be relied on to provide confidentiality or integrity, and DOD data may be compromised. + + RHEL 10 systems using encryption are required to use FIPS-compliant mechanisms for authenticating to cryptographic modules. + + FIPS 140-3 is the current standard for validating that mechanisms used to access cryptographic modules use authentication that meets DOD requirements. This allows for Security Levels 1, 2, 3, or 4 for use on a general-purpose computing system. + + Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061 + + + + + + + + RHEL-10-600720 - RHEL 10 must be configured so that password-auth uses a sufficient number of hashing rounds. + + Red Hat Enterprise Linux 10 + + Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + + Using more hashing rounds makes password cracking attacks more difficult. + + Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061 + + + + + + + + RHEL-10-600730 - RHEL 10 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords. + + Red Hat Enterprise Linux 10 + + The system must use a strong hashing algorithm to store the password. + + Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. + + Satisfies: SRG-OS-000073-GPOS-00041, SRG-OS-000120-GPOS-00061 + + + + + + + + RHEL-10-600740 - RHEL 10 must be configured to use the shadow file to store only encrypted representations of passwords. + + Red Hat Enterprise Linux 10 + + Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + + This setting ensures user and group account administration utilities are configured to store only encrypted representations of passwords. Additionally, the "crypt_style" configuration option ensures the use of a strong hashing algorithm that makes password cracking attacks more difficult. + + + + + + + + RHEL-10-600750 - RHEL 10 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. + + Red Hat Enterprise Linux 10 + + Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm are no more protected than if they are kept in plain text. + + This setting ensures user and group account administration utilities are configured to store only encrypted representations of passwords. Additionally, the "crypt_style" configuration option ensures the use of a strong hashing algorithm that makes password cracking attacks more difficult. + + + + + + + + RHEL-10-700010 - RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a Secure Shell (SSH) login. + + Red Hat Enterprise Linux 10 + + The warning message reinforces policy awareness during the login process and facilitates possible legal action against attackers. Alternatively, systems whose ownership should not be obvious should ensure use of a banner that does not provide easy attribution. + + OpenSSH uses the first occurrence of a keyword it sees, and drop-in files are read in lexicographical order at the start of the configuration. Red Hat recommends using drop-in files rather than changing base configuration files. + + + + + + + + RHEL-10-700030 - RHEL 10 must prevent a user from overriding the banner-message-enable setting for the graphical user interface. + + Red Hat Enterprise Linux 10 + + Display of a standardized and approved use notification before granting access to the operating system ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. + + For U.S. Government systems, system use notifications are required only for access via login interfaces with human users and are not required when such human interfaces do not exist. + + Satisfies: SRG-OS-000023-GPOS-00006, SRG-OS-000228-GPOS-00088 + + + + + + + + RHEL-10-700100 - RHEL 10 must prevent special devices on file systems that are imported via Network File System (NFS). + + Red Hat Enterprise Linux 10 + + The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-700105 - RHEL 10 must prevent code from being executed on file systems that are imported via Network File System (NFS). + + Red Hat Enterprise Linux 10 + + The "noexec" mount option causes the system not to execute binary files. This option must be used for mounting any file system not containing approved binary as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-700110 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via Network File System (NFS). + + Red Hat Enterprise Linux 10 + + The "nosuid" mount option causes the system not to execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-700115 - RHEL 10 must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS. + + Red Hat Enterprise Linux 10 + + When an NFS server is configured to use RPCSEC_SYS, a selected userid and groupid are used to handle requests from the remote user. The userid and groupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS method of authentication uses certificates on the server and client systems to more securely authenticate the remote mount request. + + + + + + + + RHEL-10-700120 - RHEL 10 must mount "/boot" with the "nodev" option. + + Red Hat Enterprise Linux 10 + + The only legitimate location for device files is the "/dev" directory located on the root partition. The only exception to this is chroot jails. + + + + + + + + RHEL-10-700125 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot" directory. + + Red Hat Enterprise Linux 10 + + The "nosuid" mount option causes the system not to execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-700130 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on the "/boot/efi" directory. + + Red Hat Enterprise Linux 10 + + The "nosuid" mount option causes the system not to execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-700135 - RHEL 10 must mount "/dev/shm" with the "nodev" option. + + Red Hat Enterprise Linux 10 + + The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented. + + + + + + + + RHEL-10-700140 - RHEL 10 must mount "/dev/shm" with the "noexec" option. + + Red Hat Enterprise Linux 10 + + The "noexec" mount option causes the system to not execute binary files. This option must be used for mounting any file system not containing approved binary files, as they may be incompatible. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-700145 - RHEL 10 must mount "/dev/shm" with the "nosuid" option. + + Red Hat Enterprise Linux 10 + + The "nosuid" mount option causes the system to not execute "setuid" and "setgid" files with owner privileges. This option must be used for mounting any file system not containing approved "setuid" and "setguid" files. Executing files from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + + + + + + + RHEL-10-700150 - RHEL 10 must mount "/tmp" with the "nodev" option. + + Red Hat Enterprise Linux 10 + + The "nodev" mount option causes the system to not interpret character or block special devices. Executing character or block special devices from untrusted file systems increases the opportunity for nonprivileged users to attain unauthorized administrative access. + + The only legitimate location for device files is the "/dev" directory located on the root partition, with the exception of chroot jails if implemented. + + + + + + + + RHEL-10-700400 - RHEL 10 must enable the SELinux targeted policy. + + Red Hat Enterprise Linux 10 + + Setting the SELinux policy to "targeted" or a more specialized policy ensures the system will confine processes that are likely to be targeted for exploitation, such as network or system services. + + Note: During the development or debugging of SELinux modules, it is common to temporarily place nonproduction systems in "permissive" mode. In such temporary cases, SELinux policies should be developed, and once work is completed, the system should be reconfigured to "targeted". + + + + + + + + RHEL-10-700410 - RHEL 10 must elevate the SELinux context when an administrator calls the sudo command. + + Red Hat Enterprise Linux 10 + + Without verification of the security functions, security functions may not operate correctly and the failure may go unnoticed. Security function is defined as the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based. + + Security functionality includes, but is not limited to, establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters. + + This requirement applies to operating systems performing security function verification/testing and/or systems and environments that require this functionality. + + Preventing nonprivileged users from executing privileged functions mitigates the risk that unauthorized individuals or processes may gain unnecessary access to information or privileges. + + Privileged functions include, for example, establishing accounts, performing system integrity checks, or administering cryptographic key management activities. Nonprivileged users are individuals who do not possess appropriate authorizations. Circumventing intrusion detection and prevention mechanisms or malicious code protection mechanisms are examples of privileged functions that require protection from nonprivileged users. + + + + + + + + RHEL-10-700500 - RHEL 10 must be configured so that Secure Shell (SSH) public host key files have mode "0644" or less permissive. + + Red Hat Enterprise Linux 10 + + If a public host key file is modified by an unauthorized user, the SSH service may be compromised. + + + + + + + + RHEL-10-700640 - RHEL 10 must not allow users to override Secure Shell (SSH) environment variables. + + Red Hat Enterprise Linux 10 + + SSH environment options potentially allow users to bypass access restriction in some configurations. + + OpenSSH uses the first occurrence of a keyword it sees, and drop-in files are read in lexicographical order at the start of the configuration. Red Hat recommends using drop-in files rather than changing base configuration files. + + + + + + + + RHEL-10-700650 - RHEL 10 must force a frequent session key renegotiation for Secure Shell (SSH) connections to the server. + + Red Hat Enterprise Linux 10 + + Without protection of the transmitted information, confidentiality and integrity may be compromised because unprotected communications can be intercepted and either read or altered. + + This requirement applies to both internal and external networks and all types of information system components from which information can be transmitted (e.g., servers, mobile devices, notebook computers, printers, copiers, scanners, and facsimile machines). Communication paths outside the physical protection of a controlled boundary are exposed to the possibility of interception and modification. + + Protecting the confidentiality and integrity of organizational information can be accomplished by physical means (e.g., employing physical distribution systems) or by logical means (e.g., employing cryptographic techniques). If physical means of protection are employed, then logical means (cryptography) do not have to be employed, and vice versa. + + Session key regeneration limits the chances of a session key becoming compromised. + + OpenSSH uses the first occurrence of a keyword it sees, and drop-in files are read in lexicographical order at the start of the configuration. Red Hat recommends using drop-in files rather than changing base configuration files. + + Satisfies: SRG-OS-000423-GPOS-00187, SRG-OS-000033-GPOS-00014, SRG-OS-000424-GPOS-00188 + + + + + + + + RHEL-10-700720 - RHEL 10 must not allow unattended or automatic login via the graphical user interface. + + Red Hat Enterprise Linux 10 + + Failure to restrict system access to authenticated users negatively impacts operating system security. + + + + + + + + RHEL-10-700780 - RHEL 10 must prevent a user from overriding the session lock-delay setting for the graphical user interface. + + Red Hat Enterprise Linux 10 + + A session timeout lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the information system but does not log out because of the temporary nature of the absence. Rather than relying on the user to manually lock their operating system session prior to vacating the vicinity, the GNOME desktop can be configured to identify when a user's session has idled and take action to initiate the session lock. Therefore, users should not be allowed to change session settings. + + Satisfies: SRG-OS-000029-GPOS-00010, SRG-OS-000031-GPOS-00012 + + + + + + + + RHEL-10-700810 - RHEL 10 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. + + Red Hat Enterprise Linux 10 + + A user who is at the console can reboot the system at the login screen. If restart or shutdown buttons are pressed at the login screen, this can create the risk of short-term loss of availability of systems due to reboot. + + + + + + + + RHEL-10-700820 - RHEL 10 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. + + Red Hat Enterprise Linux 10 + + A locally logged-in user who presses Ctrl-Alt-Del when at the console can reboot the system. If accidentally pressed, as could happen in the case of a mixed operating system environment, this can create the risk of short-term loss of systems' availability due to unintentional reboot. + + + + + + + + RHEL-10-700840 - RHEL 10 must disable the user list at login for graphical user interfaces. + + Red Hat Enterprise Linux 10 + + Leaving the user list enabled is a security risk because it allows anyone with physical access to the system to enumerate known user accounts without authenticated access to the system. + + + + + + + + RHEL-10-700850 - RHEL 10 must be configured to disable USB mass storage. + + Red Hat Enterprise Linux 10 + + USB mass storage permits easy introduction of unknown devices, thereby facilitating malicious activity. + + Satisfies: SRG-OS-000114-GPOS-00059, SRG-OS-000378-GPOS-00163 + + + + + + + + RHEL-10-700860 - RHEL 10 must disable Bluetooth. + + Red Hat Enterprise Linux 10 + + This requirement applies to wireless peripheral technologies (e.g., wireless mice, keyboards, displays, etc.) used with RHEL 10 systems. Wireless peripherals (e.g., Wi-Fi/Bluetooth/IR keyboards, mice and pointing devices, and near field communications [NFC]) present a unique challenge by creating an open, unsecured port on a computer. + + Wireless peripherals must meet DOD requirements for wireless data transmission and be approved for use by the authorizing official. Even though some wireless peripherals, such as mice and pointing devices, do not ordinarily carry information that must be protected, modification of communications with these wireless peripherals may be used to compromise the RHEL 10 operating system. + + Satisfies: SRG-OS-000095-GPOS-00049, SRG-OS-000300-GPOS-00118 + + + + + + + + RHEL-10-700880 - RHEL 10 must disable the graphical user interface automounter unless required. + + Red Hat Enterprise Linux 10 + + Automatically mounting file systems permits easy introduction of unknown devices, thereby facilitating malicious activity. + + Satisfies: SRG-OS-000114-GPOS-00059, SRG-OS-000378-GPOS-00163 + + + + + + + + RHEL-10-700920 - RHEL 10 must automatically exit interactive command shell user sessions after 15 minutes of inactivity. + + Red Hat Enterprise Linux 10 + + Terminating an idle interactive command shell user session within a short time period reduces the window of opportunity for unauthorized personnel to take control of it when left unattended in a virtual terminal or physical console. + + Satisfies: SRG-OS-000163-GPOS-00072, SRG-OS-000029-GPOS-00010 + + + + + + + + RHEL-10-700930 - RHEL 10 must be configured with a timeout interval for the Secure Shell (SSH) daemon. + + Red Hat Enterprise Linux 10 + + Terminating an idle SSH session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or console port that has been left unattended. In addition, quickly terminating an idle SSH session will also free up resources committed by the managed network element. + + Terminating network connections associated with communications sessions includes, for example, deallocating associated TCP/IP address/port pairs at the operating system level and deallocating networking assignments at the application level if multiple application sessions are using a single operating system-level network connection. This does not mean that the operating system terminates all sessions or network access; it only ends the inactive session and releases the resources associated with that session. + + RHEL 10 uses "/etc/ssh/sshd_config" for configurations of OpenSSH. Within the "sshd_config", the product of the values of "ClientAliveInterval" and "ClientAliveCountMax" are used to establish the inactivity threshold. + + The "ClientAliveInterval" is a timeout interval in seconds after which if no data has been received from the client, sshd will send a message through the encrypted channel to request a response from the client. + + The "ClientAliveCountMax" is the number of client alive messages that may be sent without sshd receiving any messages back from the client. If this threshold is met, sshd will disconnect the client. + + For more information on these settings and others, refer to the sshd_config man pages. + + Satisfies: SRG-OS-000163-GPOS-00072, SRG-OS-000279-GPOS-00109, SRG-OS-000395-GPOS-00175 + + + + + + + + RHEL-10-700940 - RHEL 10 must not default to the graphical display manager unless approved. + + Red Hat Enterprise Linux 10 + + Unnecessary service packages must not be installed to decrease the attack surface of the system. Graphical display managers have a long history of security vulnerabilities and must not be used unless approved and documented. + + + + + + + + RHEL-10-700950 - RHEL 10 must disable the systemd Ctrl-Alt-Delete burst key sequence. + + Red Hat Enterprise Linux 10 + + A locally logged-on user who presses Ctrl-Alt-Delete when at the console can reboot the system. If accidentally pressed, as could happen in the case of a mixed operating system environment, this can create the risk of short-term loss of availability of systems due to unintentional reboot. + + In a graphical user environment, risk of unintentional reboot from the Ctrl-Alt-Delete sequence is reduced because the user will be prompted before any action is taken. + + + + + + + + RHEL-10-700960 - RHEL 10 must disable the x86 Ctrl-Alt-Delete key sequence. + + Red Hat Enterprise Linux 10 + + A locally logged-on user who presses Ctrl-Alt-Delete when at the console can reboot the system. If accidentally pressed, as could happen in the case of a mixed operating system environment, this can create the risk of short-term loss of systems availability due to unintentional reboot. + + In a graphical user environment, risk of unintentional reboot from the Ctrl-Alt-Delete sequence is reduced because the user will be prompted before any action is taken. + + + + + + + + RHEL-10-700980 - RHEL 10 must disable the ability of systemd to spawn an interactive boot process. + + Red Hat Enterprise Linux 10 + + Using interactive or recovery boot, the console user could disable auditing, firewalls, or other services, weakening system security. + + + + + + + + RHEL-10-700990 - RHEL 10 must disable virtual system calls. + + Red Hat Enterprise Linux 10 + + System calls are special routines in the Linux kernel, which userspace applications ask to do privileged tasks. Invoking a system call is an expensive operation because the processor must interrupt the currently executing task and switch context to kernel mode and then back to userspace after the system call completes. Virtual system calls map into user space a page that contains some variables and the implementation of some system calls. This allows the system calls to be executed in userspace to alleviate the context-switching expense. + + Virtual system calls provide an opportunity of attack for a user who has control of the return instruction pointer. Disabling virtual system calls help to prevent return-oriented programming attacks via buffer overflows and overruns. + + + + + + + + RHEL-10-701000 - RHEL 10 must clear the page allocator to prevent use-after-free attacks. + + Red Hat Enterprise Linux 10 + + Poisoning writes an arbitrary value to freed pages, so any modification or reference to that page after being freed or before being initialized will be detected and prevented. This prevents many types of use-after-free vulnerabilities at little performance cost. It also prevents data leakage and detection of corrupted memory. + + + + + + + + RHEL-10-701010 - RHEL 10 must clear memory when it is freed to prevent use-after-free attacks. + + Red Hat Enterprise Linux 10 + + Some adversaries launch attacks with the intent of executing code in nonexecutable regions of memory or in memory locations that are prohibited. Security safeguards employed to protect memory include, for example, data execution prevention and address space layout randomization. Data execution prevention safeguards can be either hardware-enforced or software-enforced, with hardware providing the greater strength of mechanism. + + Poisoning writes an arbitrary value to freed pages, so any modification or reference to that page after being freed or before being initialized will be detected and prevented. This prevents many types of use-after-free vulnerabilities at little performance cost. It also prevents data leakage and detection of corrupted memory. + + "init_on_free" is a Linux kernel boot parameter that enhances security by initializing memory regions when they are freed, preventing data leakage. This process ensures that stale data in freed memory cannot be accessed by malicious programs. + + SLUB canaries add a randomized value (canary) at the end of SLUB-allocated objects to detect memory corruption caused by buffer overflows or underflows. Redzoning adds padding (red zones) around SLUB-allocated objects to detect overflows or underflows by triggering a fault when adjacent memory is accessed. SLUB canaries are often more efficient and provide stronger detection against buffer overflows compared to redzoning. SLUB canaries are supported in hardened Linux kernels such as the ones provided by Linux-hardened. + + SLAB objects are blocks of physically contiguous memory. SLUB is the unqueued SLAB allocator. + + + + + + + + RHEL-10-701020 - RHEL 10 must enable mitigations against processor-based vulnerabilities. + + Red Hat Enterprise Linux 10 + + Kernel page-table isolation is a kernel feature that mitigates the Meltdown security vulnerability and hardens the kernel against attempts to bypass kernel address space layout randomization (KASLR). + + Satisfies: SRG-OS-000433-GPOS-00193, SRG-OS-000095-GPOS-00049 + + + + + + + + RHEL-10-701030 - RHEL 10 must restrict access to the kernel message buffer. + + Red Hat Enterprise Linux 10 + + Preventing unauthorized information transfers mitigates the risk of information, including encrypted representations of information, produced by the actions of prior users/roles (or the actions of processes acting on behalf of prior users/roles) from being available to any current users/roles (or current processes) that obtain access to shared system resources (e.g., registers, main memory, hard disks) after those resources have been released back to information systems. The control of information in shared resources is also commonly referred to as object reuse and residual information protection. + + This requirement generally applies to the design of an information technology product, but it can also apply to the configuration of information system components that are, or use, such products. This can be verified by acceptance/validation processes in DOD or other government agencies. + + There may be shared resources with configurable protections (e.g., files in storage) that may be assessed on specific information system components. + + Restricting access to the kernel message buffer limits access to only root. This prevents attackers from gaining additional system information as a nonprivileged user. + + Satisfies: SRG-OS-000132-GPOS-00067, SRG-OS-000138-GPOS-00069 + + + + + + + + RHEL-10-701040 - RHEL 10 must prevent kernel profiling by nonprivileged users. + + Red Hat Enterprise Linux 10 + + Preventing unauthorized information transfers mitigates the risk of information, including encrypted representations of information, produced by the actions of prior users/roles (or the actions of processes acting on behalf of prior users/roles) from being available to any current users/roles (or current processes) that obtain access to shared system resources (e.g., registers, main memory, hard disks) after those resources have been released back to information systems. The control of information in shared resources is also commonly referred to as object reuse and residual information protection. + + This requirement generally applies to the design of an information technology product, but it can also apply to the configuration of information system components that are, or use, such products. This can be verified by acceptance/validation processes in DOD or other government agencies. + + There may be shared resources with configurable protections (e.g., files in storage) that may be assessed on specific information system components. + + Setting the "kernel.perf_event_paranoid" kernel parameter to "2" prevents attackers from gaining additional system information as a nonprivileged user. + + Satisfies: SRG-OS-000132-GPOS-00067, SRG-OS-000138-GPOS-00069 + + + + + + + + RHEL-10-701050 - RHEL 10 must prevent the loading of a new kernel for later execution. + + Red Hat Enterprise Linux 10 + + Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and has been provided by a trusted vendor. + + Disabling kexec_load prevents an unsigned kernel image (that could be a windows kernel or modified vulnerable kernel) from being loaded. Kexec can be used to subvert the entire secureboot process and should be avoided at all costs, especially because it can load unsigned kernel images. + + + + + + + + RHEL-10-701060 - RHEL 10 must restrict exposed kernel pointer address access. + + Red Hat Enterprise Linux 10 + + Exposing kernel pointers (through procfs or "seq_printf()") exposes kernel writable structures, which may contain functions pointers. If a write vulnerability occurs in the kernel, allowing write access to any of this structure, the kernel can be compromised. This option disallows any program without the CAP_SYSLOG capability to get the addresses of kernel pointers by replacing them with "0". + + Satisfies: SRG-OS-000132-GPOS-00067, SRG-OS-000433-GPOS-00192 + + + + + + + + RHEL-10-701070 - RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on hardlinks. + + Red Hat Enterprise Linux 10 + + By enabling the "fs.protected_hardlinks" kernel parameter, users can no longer create soft or hard links to files they do not own. Disallowing such hardlinks mitigates vulnerabilities based on insecure file systems accessed by privileged programs, avoiding an exploitation vector exploiting unsafe use of open() or creat(). + + Satisfies: SRG-OS-000312-GPOS-00122, SRG-OS-000312-GPOS-00123, SRG-OS-000324-GPOS-00125 + + + + + + + + RHEL-10-701080 - RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks. + + Red Hat Enterprise Linux 10 + + By enabling the "fs.protected_symlinks" kernel parameter, symbolic links are permitted to be followed only when outside a sticky world-writable directory, or when the user identifier (UID) of the link and follower match, or when the directory owner matches the symlink's owner. Disallowing such symlinks helps mitigate vulnerabilities based on insecure file systems accessed by privileged programs, avoiding an exploitation vector exploiting unsafe use of open() or creat(). + + Satisfies: SRG-OS-000312-GPOS-00122, SRG-OS-000312-GPOS-00123, SRG-OS-000324-GPOS-00125 + + + + + + + + RHEL-10-701090 - RHEL 10 must disable the "kernel.core_pattern". + + Red Hat Enterprise Linux 10 + + A core dump includes a memory image taken at the time the operating system terminates an application. The memory image could contain sensitive data and is generally useful only for developers trying to debug problems. + + + + + + + + RHEL-10-701100 - RHEL 10 must be configured to disable the Controller Area Network (CAN) kernel module. + + Red Hat Enterprise Linux 10 + + Disabling CAN protects the system against exploitation of any flaws in its implementation. + + + + + + + + RHEL-10-701130 - RHEL 10 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. + + Red Hat Enterprise Linux 10 + + ASLR makes it more difficult for an attacker to predict the location of attack code they have introduced into a process's address space during an attempt at exploitation. Additionally, ASLR makes it more difficult for an attacker to know the location of existing code to repurpose it using return-oriented programming techniques. + + + + + + + + RHEL-10-001000 - RHEL 10 must be a vendor-supported release. + + Red Hat Enterprise Linux 10 + + An operating system release is considered "supported" if the vendor continues to provide security patches for the product. With an unsupported release, it will not be possible to resolve security issues discovered in the system software. + + Red Hat offers the Extended Update Support (EUS) add-on to a Red Hat Enterprise Linux subscription, for a fee, for customers who wish to standardize on a specific minor release for an extended period. + + End-of-life dates for Red Hat Linux 10 releases are as follows: + - Current end of Full Support for Red Hat Linux 10 is 31 May 2030. + - Current end of Maintenance Support for Red Hat Linux 10 is 31 May 2035. + - Current end of Extended Life Cycle Support (ELS) for Red Hat Linux 9 is 31 May 2038. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + /etc/security/faillock.conf + ^\s*even_deny_root\s*$ + 1 + + + /etc/sysctl.conf + (?:^|\.*\n)\s*net\.ipv6\.conf\.all\.disable_ipv6\s*=\s*(\d+)\s*$ + 1 + + + + \.conf$ + (?:^|\.*\n)\s*net\.ipv6\.conf\.all\.disable_ipv6\s*=\s*(\d+)\s*$ + 1 + + + + oval:mil.disa.stig.ind:obj:10001201 + oval:mil.disa.stig.ind:obj:10001202 + + + + /proc/cmdline + \bipv6\.disable=1\b + 1 + + + /etc/fstab + ^\s*[^#\s]+\s+/boot/efi\s+(\S+)\s+\S+\s+\S+\s+\S+\s*$ + 1 + + + + oval:mil.disa.stig.ind:obj:20000003 + oval:mil.disa.stig.ind:obj:20000004 + + + + + /etc/rsyslog.conf + ^\*\.\*\s+action\((\s*(?:[^#\)]*(?:#.*$)?\n)*[^#\)]*)\) + 1 + + + + /etc/rsyslog.d + ^.*\.conf$ + ^\*\.\*\s+action\((\s*(?:[^#\)]*(?:#.*$)?\n)*[^#\)]*)\) + 1 + + + /etc/libuser.conf + ^\[defaults]((?:\r?\n(?:[^[\r\n].*)?)*) + 1 + + + /etc/libuser.conf + ^\s*crypt_style\s*=\s*(\S+)\s*$ + 1 + + + /etc/login.defs + ^\s*ENCRYPT_METHOD\s+([^#\r\n]*) + 1 + + + /etc/shadow + ^[^:]+:([^:]*): + 1 + + + + oval:mil.disa.stig.ind:obj:23023200 + oval:mil.disa.stig.ind:ste:23023200 + oval:mil.disa.stig.ind:ste:23023201 + + + + /etc/pam.d + password-auth + ^[ \t]*password[ \t]+sufficient[ \t]+pam_unix\.so(?:[ \t]+|(?:[ \t][^#\r\f\n]+[ \t]))sha512(?:[ \t]|$) + 1 + + + /etc/yum.repos.d + \.repo$ + ^\s*\[[^]]+\]\s*\n(?:[^[]*\n)* + 1 + + + /etc/dnf/dnf.conf + ^\s*localpkg_gpgcheck\s*=\s*(\w+)\b\s*$ + 1 + + + + /etc/sudoers + ^(?!#).*\s+NOPASSWD.*$ + 1 + + + + /etc/sudoers.d + ^.*$ + ^(?!#).*\s+NOPASSWD.*$ + 1 + + + /etc/selinux/config + ^\s*SELINUXTYPE\s*=\s*(\w+)\s*$ + 1 + + + + /etc/audit/auditd.conf + ^\s*log_file\s*=\s*(\S+)/\S+\s*$ + 1 + + + /etc/fstab + ^\s*[^#\s]+\s+/boot\s+\S+\s+(\S+)\s+\S+\s+\S+\s*$ + 1 + + + /etc/fstab + ^\s*[^#\s][^\s]*\s+[^\s]+\s+nfs[^\s]*\s+([^\s]+) + 0 + + + /etc/fstab + ^\s*[^#\s][^\s]*\s+[^\s]+\s+nfs[^\s]*\s+([^\s]+) + 1 + + + /etc/login.defs + ^\s*CREATE_HOME\s+([^#\s]+) + 1 + + + /etc/gdm/custom.conf + ^\s*\[daemon\]\s+[#\s\w=]*^\s*AutomaticLoginEnable=(\w+)\s*$ + 1 + + + /etc/security/faillock.conf + ^\s*deny\s*=\s*([\d]+)\s*$ + 1 + + + /etc/security/faillock.conf + ^\s*fail_interval\s*=\s*([\d]+)\s*$ + 1 + + + /etc/security/faillock.conf + ^\s*unlock_time\s*=\s*([\d]+)\s*$ + 1 + + + /etc/security/faillock.conf + ^\s*dir\s*=\s*(\S+)\s*(?:#.*)?$ + 1 + + + /etc/security/faillock.conf + ^\s*audit\s*$ + 1 + + + /etc/pam.d/password-auth + ^\s*password\s+(?:required|requisite)\s+pam_pwquality\.so\b + 1 + + + + oval:mil.disa.stig.ind:obj:23035701 + oval:mil.disa.stig.ind:obj:23035702 + + + + /etc/security/pwquality.conf + ^\s*ucredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*ucredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23035801 + oval:mil.disa.stig.ind:obj:23035802 + + + + /etc/security/pwquality.conf + ^\s*lcredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*lcredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23035901 + oval:mil.disa.stig.ind:obj:23035902 + + + + /etc/security/pwquality.conf + ^\s*dcredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*dcredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23036001 + oval:mil.disa.stig.ind:obj:23036002 + + + + /etc/security/pwquality.conf + ^\s*maxclassrepeat\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*maxclassrepeat\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23036101 + oval:mil.disa.stig.ind:obj:23036102 + + + + /etc/security/pwquality.conf + ^\s*maxrepeat\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*maxrepeat\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23036201 + oval:mil.disa.stig.ind:obj:23036202 + + + + /etc/security/pwquality.conf + ^\s*minclass\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*minclass\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23036301 + oval:mil.disa.stig.ind:obj:23036302 + + + + /etc/security/pwquality.conf + ^\s*difok\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*difok\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23036901 + oval:mil.disa.stig.ind:obj:23036902 + + + + /etc/security/pwquality.conf + ^\s*minlen\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*minlen\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + /etc/default/useradd + (?i)^\s*INACTIVE\s*=\s*(-?\d+)\s*$ + 1 + + + + oval:mil.disa.stig.ind:obj:23037501 + oval:mil.disa.stig.ind:obj:23037502 + + + + /etc/security/pwquality.conf + ^\s*ocredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*ocredit\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23037701 + oval:mil.disa.stig.ind:obj:23037702 + + + + /etc/security/pwquality.conf + ^\s*dictcheck\s*=\s*([-\d]+)\s*(?:#.*)?$ + 1 + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*dictcheck\s*=\s*([-\d]+)\s*(?:#.*)?$ + 1 + + + /etc/login.defs + ^\s*FAIL_DELAY\s+(\d+)\s*$ + 1 + + + /etc/login.defs + ^\s*UMASK\s+([^#\s]+) + 1 + + + /etc/csh.cshrc + ^\s*(?i)umask\s*(\d+)\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+-S\s+execve\s+-C\s+uid!=euid\s+-F\s+euid=0\s*((\s+-k\s+|-F\s+key=)\S+\s*)?$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+-S\s+execve\s+-C\s+uid!=euid\s+-F\s+euid=0\s*((\s+-k\s+|-F\s+key=)\S+\s*)?$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+-S\s+execve\s+-C\s+gid!=egid\s+-F\s+egid=0\s*((\s+-k\s+|-F\s+key=)\S+\s*)?$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+-S\s+execve\s+-C\s+gid!=egid\s+-F\s+egid=0\s*((\s+-k\s+|-F\s+key=)\S+\s*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*action_mail_acct\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*local_events\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*name_format\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*log_format\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/su\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+setxattr\s+|(\s+|,)setxattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+setxattr\s+|(\s+|,)setxattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+setxattr\s+|(\s+|,)setxattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+setxattr\s+|(\s+|,)setxattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/chage\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=\/usr\/bin\/chcon\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/ssh-agent\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/passwd\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/umount\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/unix_update\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/postdrop\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/postqueue\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/semanage\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/setfiles\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/userhelper\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/setsebool\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/unix_chkpwd\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/libexec/openssh/ssh-keysign\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/setfacl\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/pam_timestamp_check\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/newgrp\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+init_module\s+|(\s+|,)init_module(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+init_module\s+|(\s+|,)init_module(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+finit_module\s+|(\s+|,)finit_module(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+finit_module\s+|(\s+|,)finit_module(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/gpasswd\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+delete_module\s+|(\s+|,)delete_module(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+delete_module\s+|(\s+|,)delete_module(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/crontab\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/chsh\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+truncate\s+|(\s+|,)truncate(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+truncate\s+|(\s+|,)truncate(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+truncate\s+|(\s+|,)truncate(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+truncate\s+|(\s+|,)truncate(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+ftruncate\s+|(\s+|,)ftruncate(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+ftruncate\s+|(\s+|,)ftruncate(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+ftruncate\s+|(\s+|,)ftruncate(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+ftruncate\s+|(\s+|,)ftruncate(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+creat\s+|(\s+|,)creat(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+creat\s+|(\s+|,)creat(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+creat\s+|(\s+|,)creat(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+creat\s+|(\s+|,)creat(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+open\s+|(\s+|,)open(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+open\s+|(\s+|,)open(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+open\s+|(\s+|,)open(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+open\s+|(\s+|,)open(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+openat\s+|(\s+|,)openat(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+openat\s+|(\s+|,)openat(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+openat\s+|(\s+|,)openat(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+openat\s+|(\s+|,)openat(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+open_by_handle_at\s+|(\s+|,)open_by_handle_at(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+open_by_handle_at\s+|(\s+|,)open_by_handle_at(\s+|,))).*-F\s+exit=-EPERM\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+open_by_handle_at\s+|(\s+|,)open_by_handle_at(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+open_by_handle_at\s+|(\s+|,)open_by_handle_at(\s+|,))).*-F\s+exit=-EACCES\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+chown\s+|(\s+|,)chown(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+chown\s+|(\s+|,)chown(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+lchown\s+|(\s+|,)lchown(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+lchown\s+|(\s+|,)lchown(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fchownat\s+|(\s+|,)fchownat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fchownat\s+|(\s+|,)fchownat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fchown\s+|(\s+|,)fchown(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fchown\s+|(\s+|,)fchown(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+chmod\s+|(\s+|,)chmod(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+chmod\s+|(\s+|,)chmod(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fchmod\s+|(\s+|,)fchmod(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fchmod\s+|(\s+|,)fchmod(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fchmodat\s+|(\s+|,)fchmodat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fchmodat\s+|(\s+|,)fchmodat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/sudo\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/usermod\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/chacl\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/kmod\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/aide.conf + ^\s*/usr/sbin/auditctl\s+\S+ + 1 + + + /etc/aide.conf + ^\s*/usr/sbin/auditd\s+\S+ + 1 + + + /etc/aide.conf + ^\s*/usr/sbin/ausearch\s+\S+ + 1 + + + /etc/aide.conf + ^\s*/usr/sbin/aureport\s+\S+ + 1 + + + /etc/aide.conf + ^\s*/usr/sbin/augenrules\s+\S+ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*overflow_action\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*space_left\s*=\s*([\d]+)%\s*(?:#.*)?$ + 1 + + + /etc/modprobe.d + .* + ^[ \t]*install[ \t]+can[ \t]+/bin/false[ \t]*$ + 1 + + + /etc/modprobe.d + .* + ^[ \t]*blacklist[ \t]+can[ \t]*$ + 1 + + + /etc/modprobe.d + .* + ^[ \t]*install[ \t]+usb-storage[ \t]+/bin/false[ \t]*$ + 1 + + + /etc/modprobe.d + .* + ^[ \t]*blacklist[ \t]+usb-storage[ \t]*$ + 1 + + + /etc/modprobe.d + .* + ^[ \t]*install[ \t]+bluetooth[ \t]+/bin/false[ \t]*$ + 1 + + + /etc/modprobe.d + .* + ^[ \t]*blacklist[ \t]+bluetooth[ \t]*$ + 1 + + + /etc/fstab + ^\s*[^#\s]+\s+/dev/shm\s+\S+\s+(\S+)\s+\S+\s+\S+\s*$ + 1 + + + /etc/fstab + ^\s*[^#\s]+\s+/dev/shm\s+\S+\s+(\S+)\s+\S+\s+\S+\s*$ + 1 + + + oval:mil.disa.stig.linux:var:23051100 + + + /etc/fstab + ^\s*[^#\s]+\s+/tmp\s+\S+\s+(\S+)\s+\S+\s+\S+\s*$ + 1 + + + oval:mil.disa.stig.linux:var:23051700 + + + /etc/fstab + ^\s*[^#\s]+\s+/var/log/audit\s+\S+\s+(\S+)\s+\S+\s+\S+\s*$ + 1 + + + /etc/fstab + ^\s*[^#\s]+\s+/var/log/audit\s+\S+\s+(\S+)\s+\S+\s+\S+\s*$ + 1 + + + + /etc/ssh/sshd_config + ^\s*RekeyLimit\s+\d+[kmg]?\s+\d+[smdhw]?\s* + 1 + + + + /etc/ssh/sshd_config.d + ^.+\.conf$ + ^\s*RekeyLimit\s+\d+[kmg]?\s+\d+[smdhw]?\s* + 1 + + + /etc/postfix/main.cf + ^smtpd_client_restrictions[ \t]*=[ \t]*permit_mynetworks[, \t]+reject[ \t]*$ + 1 + + + /etc/ssh/sshd_config + ^\s*(?i)LogLevel(?-i)[ \t]+([\w\"]+)[\s]*(?:|(?:#.*))?$ + 1 + + + /etc/ssh/sshd_config.d + .+ + ^\s*(?i)LogLevel(?-i)[ \t]+([\w\"]+)[\s]*(?:|(?:#.*))?$ + 1 + + + + oval:mil.disa.stig.ind:obj:23481500 + oval:mil.disa.stig.ind:obj:23481501 + + + + + oval:mil.disa.stig.ind:obj:23499001 + oval:mil.disa.stig.ind:obj:23499002 + + + + /etc/systemd/system.conf + ^\s*CtrlAltDelBurstAction\s*=\s*(\S+)\s*$ + 1 + + + /etc/systemd/system.conf.d + ^.+\.conf$ + ^\s*CtrlAltDelBurstAction\s*=\s*(\S+)\s*$ + 1 + + + /etc/sudoers + ^\s*Defaults\s+!targetpw\s*$ + 1 + + + /etc/sudoers + ^\s*[#@]includedir\s+(\S+)\s*$ + 1 + + + + ^\s*Defaults\s+!targetpw\s*$ + 1 + + + /etc/sudoers + ^\s*Defaults\s+!rootpw\s*$ + 1 + + + + ^\s*Defaults\s+!rootpw\s*$ + 1 + + + /etc/sudoers + ^\s*Defaults\s+!runaspw\s*$ + 1 + + + + ^\s*Defaults\s+!runaspw\s*$ + 1 + + + + /etc/sudoers + ^\s*Defaults\s+timestamp_timeout\s*=\s*([-\d]+)\s*$ + 1 + + + + /etc/sudoers.d + ^.*$ + ^\s*Defaults\s+timestamp_timeout\s*=\s*([-\d]+)\s*$ + 1 + + + + oval:mil.disa.stig.ind:obj:23764300 + oval:mil.disa.stig.ind:obj:23764301 + + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/bin/sudoedit\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/pam.d + system-auth + ^[ \t]*password[ \t]+sufficient[ \t]+pam_unix\.so(?:[ \t]+|(?:[ \t][^#\r\f\n]+[ \t]))sha512(?:[ \t]|$) + 1 + + + /etc/fstab + ^\s*[^#\s]+\s+/boot/efi\s+\S+\s+(\S+)\s+\S+\s+\S+\s*$ + 1 + + + /etc/pam.d/system-auth + \bnullok\b + 1 + + + /etc/pam.d/password-auth + \bnullok\b + 1 + + + /etc/audit/auditd.conf + (?i)^\s*space_left_action\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+rmdir\s+|(\s+|,)rmdir(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+rmdir\s+|(\s+|,)rmdir(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/shadow + ^[^:]+::[^:]*:[^:]*: + 1 + + + + /etc/pam.d/system-auth + ^\s*password\s+(?:required|requisite)\s+(.*)$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+rename\s+|(\s+|,)rename(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+rename\s+|(\s+|,)rename(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+renameat\s+|(\s+|,)renameat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+renameat\s+|(\s+|,)renameat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+unlink\s+|(\s+|,)unlink(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+unlink\s+|(\s+|,)unlink(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+unlinkat\s+|(\s+|,)unlinkat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+unlinkat\s+|(\s+|,)unlinkat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fsetxattr\s+|(\s+|,)fsetxattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fsetxattr\s+|(\s+|,)fsetxattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fsetxattr\s+|(\s+|,)fsetxattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fsetxattr\s+|(\s+|,)fsetxattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fremovexattr\s+|(\s+|,)fremovexattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fremovexattr\s+|(\s+|,)fremovexattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fremovexattr\s+|(\s+|,)fremovexattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fremovexattr\s+|(\s+|,)fremovexattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+lremovexattr\s+|(\s+|,)lremovexattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+lremovexattr\s+|(\s+|,)lremovexattr(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+lremovexattr\s+|(\s+|,)lremovexattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+lremovexattr\s+|(\s+|,)lremovexattr(\s+|,))).*-F\s+auid=0(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/audit/audit.rules + + 1 + + + /etc/grub2.cfg + ^\s*set\s+superusers\s*=\s*"(\S+)"\s*$ + 1 + + + /boot/grub2/user.cfg + ^\s*GRUB2_PASSWORD=(\S+)\b + 1 + + + /boot/loader/entries + ^.*\.conf$ + ^options\s+(.*)$ + 1 + + + /etc/default/grub + ^GRUB_CMDLINE_LINUX="(.*)" + 1 + + + + oval:mil.disa.stig.ind:obj:23049500 + oval:mil.disa.stig.ind:obj:25780502 + + + + + oval:mil.disa.stig.ind:obj:23049501 + oval:mil.disa.stig.ind:obj:25780503 + + + + /etc/modprobe.conf + ^[ \t]*install[ \t]+can[ \t]+/bin/false[ \t]*$ + 1 + + + /etc/modprobe.conf + ^[ \t]*blacklist[ \t]+can[ \t]*$ + 1 + + + /etc/dnf/dnf.conf + ^gpgcheck=(.*)$ + 1 + + + /etc/fstab + ^\s*[^#\s][^\s]*\s+[^\s]+\s+nfs[^\s]*\s+([^\s]+) + 1 + + + /etc/ssh/sshd_config + ^\s*(?i)banner(?-i)[ \t\"]+([\w\/]+)[\"\s]*(?:|(?:#.*))?$ + 1 + + + /etc/ssh/sshd_config.d + .+ + ^\s*(?i)banner(?-i)[ \t\"]+([\w\/]+)[\"\s]*(?:|(?:#.*))?$ + 1 + + + + oval:mil.disa.stig.ind:obj:25798100 + oval:mil.disa.stig.ind:obj:25798101 + + + + /etc/ssh/sshd_config + ^\s*(?i)banner(?-i)[ \t]*(?:none[\s]*|(?:#.*))?$ + 1 + + + /etc/ssh/sshd_config.d + .+ + ^\s*(?i)banner(?-i)[ \t]*(?:none[\s]*|(?:#.*))?$ + 1 + + + + oval:mil.disa.stig.ind:obj:25798103 + oval:mil.disa.stig.ind:obj:25798104 + + + + + /etc/ssh/sshd_config + ^\s*include\s+(.*)\s*$ + 1 + + + /etc/crypto-policies/back-ends/opensshserver.config + ^\s*(?i)Ciphers(?-i)[ \t]+(\S+)[\s]*(?:|(?:#.*))?$ + 1 + + + /etc/crypto-policies/back-ends/opensshserver.config + ^\s*MACs\s+(\S+)\s*$ + 1 + + + /etc/ssh/sshd_config + ^\s*(?i)ClientAliveInterval(?-i)[ \t]+([\w\"]+)[\s]*(?:|(?:#.*))?$ + 1 + + + /etc/ssh/sshd_config.d + .+ + ^\s*(?i)ClientAliveInterval(?-i)[ \t]+([\w\"]+)[\s]*(?:|(?:#.*))?$ + 1 + + + + oval:mil.disa.stig.ind:obj:25799600 + oval:mil.disa.stig.ind:obj:25799601 + + + + + .* + ^/org/gnome/login-screen/banner-message-enable$ + 1 + + + /etc/dconf/db/local.d + 00-security-settings + ^\s*\[org\/gnome\/desktop\/media-handling]\s*\n+[^\[]*automount-open\s*=\s*(\w+)$ + 1 + + + /etc/dconf/profile/user + ^\s*system-db\s*:\s*local\s*$ + 1 + + + /etc/dconf/profile/user + ^system-db:(\S+)\s*$ + 1 + + + + .* + ^/org/gnome/desktop/screensaver/lock-delay$ + 1 + + + /etc/dconf/db/local.d/locks + ^.*$ + ^\s*\/org\/gnome\/login-screen\/disable-restart-buttons$ + 1 + + + /etc/dconf/db/local.d/locks + .* + ^/org/gnome/settings-daemon/plugins/media-keys/logout$ + 1 + + + /etc/dconf/db/local.d + .+ + ^\s*\[org\/gnome\/login-screen]\s*\n+[^\[]*disable-user-list\s*=\s*(\w+)$ + 1 + + + /etc/login.defs + ^\s*PASS_MAX_DAYS\s+(\d+) + 1 + + + oval:mil.disa.stig.defs:var:25804500 + + + /etc/group + ^[^:#]*:[^:]*:(\d+) + 1 + + + /etc/group + ^[^:]*:[^:]*:([^:]+): + 1 + + + oval:mil.disa.stig.defs:var:25806100 + + + + oval:mil.disa.stig.ind:obj:25806801 + oval:mil.disa.stig.ind:obj:25806802 + + + + /etc/profile + ^[^#]*\s*TMOUT=(\d+)\s*$ + 1 + + + + /etc/profile.d + ^.+\.sh$ + ^[^#]*\s*TMOUT=(\d+)\s*$ + 1 + + + /etc/bashrc + ^[^#]*\s*(?i)umask\s*(\d+)\s*$ + 1 + + + /etc/profile + ^(?i)\s*umask\s+([^#\s]+) + 1 + + + + /etc/sudoers + ^(?!#).*\s+!\s*authenticate.*$ + 1 + + + + /etc/sudoers.d + ^.*$ + ^(?!#).*\s+!\s*authenticate.*$ + 1 + + + + /etc/sudoers + ^\s*ALL\s+ALL\=\(ALL(?:|\:ALL)\)\s+ALL\s*$ + 1 + + + + /etc/sudoers.d + ^.*$ + ^\s*ALL\s+ALL\=\(ALL(?:|\:ALL)\)\s+ALL\s*$ + 1 + + + /etc/pam.d/su + ^\s*auth\s+(?:required|requisite)\s+pam_wheel\.so(?:\s|$) + 1 + + + + oval:mil.disa.stig.ind:obj:25809101 + oval:mil.disa.stig.ind:obj:25809102 + + + + /etc/security/pwquality.conf + ^\s*retry\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*retry\s*=\s*(-?\d*)\s*(?:#.*)?$ + 1 + + + /etc/pam.d/password-auth + ^\s*password\s+sufficient\s+pam_unix\.so\s+[^#\n]*\brounds=(\d+)\b + 1 + + + /etc/pam.d/system-auth + ^\s*password\s+sufficient\s+pam_unix\.so\s+[^#\n]*\brounds=(\d+)\b + 1 + + + + oval:mil.disa.stig.ind:obj:25810101 + oval:mil.disa.stig.ind:obj:25810102 + + + + /etc/security/pwquality.conf + ^\s*enforce_for_root\s*(?:#.*)?$ + 1 + + + + /etc/security/pwquality.conf.d + \.conf$ + ^\s*enforce_for_root\s*(?:#.*)?$ + 1 + + + /etc/pam.d/sudo + ^\s*[^#\n]*\bpam_succeed_if\b + 1 + + + /etc/opensc.conf + (?i)^\s*card_drivers\s*=(.*); + 1 + + + + oval:mil.disa.stig.ind:obj:25814301 + oval:mil.disa.stig.ind:obj:25814302 + + + + + /etc/rsyslog.conf + + 1 + + + + /etc/rsyslog.d + ^.*\.conf$ + + 1 + + + + oval:mil.disa.stig.ind:obj:25814403 + oval:mil.disa.stig.ind:obj:25814406 + + + + + oval:mil.disa.stig.ind:obj:25814404 + oval:mil.disa.stig.ind:obj:25814407 + + + + + oval:mil.disa.stig.ind:obj:25814405 + oval:mil.disa.stig.ind:obj:25814408 + + + + /etc/rsyslog.conf + ^[ \t]*(?:\S+;auth\.\*|auth\.\*;\S+|auth\.\*|\S+;auth\.\*;\S+)[ \t]+\S+\s*$ + 1 + + + /etc/rsyslog.conf + ^[ \t]*(?:\S+;authpriv\.\*|authpriv\.\*;\S+|authpriv\.\*|\S+;authpriv\.\*;\S+)[ \t]+\S+\s*$ + 1 + + + /etc/rsyslog.conf + ^[ \t]*(?:\S+;daemon\.\*|daemon\.\*;\S+|daemon\.\*|\S+;daemon\.\*;\S+)[ \t]+\S+\s*$ + 1 + + + /etc/rsyslog.d + ^.*\.conf$ + ^[ \t]*(?:\S+;auth\.\*|auth\.\*;\S+|auth\.\*|\S+;auth\.\*;\S+)[ \t]+\S+\s*$ + 1 + + + /etc/rsyslog.d + ^.*\.conf$ + ^[ \t]*(?:\S+;authpriv\.\*|authpriv\.\*;\S+|authpriv\.\*|\S+;authpriv\.\*;\S+)[ \t]+\S+\s*$ + 1 + + + /etc/rsyslog.d + ^.*\.conf$ + ^[ \t]*(?:\S+;daemon\.\*|daemon\.\*;\S+|daemon\.\*|\S+;daemon\.\*;\S+)[ \t]+\S+\s*$ + 1 + + + + oval:mil.disa.stig.ind:obj:25814901 + oval:mil.disa.stig.ind:obj:25814902 + + + + + /etc/rsyslog.conf + ^\*\.\*\s+@@(\S+) + 1 + + + + /etc/rsyslog.d + ^.*\.conf$ + ^\*\.\*\s+@@(\S+) + 1 + + + oval:mil.disa.stig.defs:var:25815500 + + + /etc/audit/auditd.conf + (?i)^\s*admin_space_left\s*=\s*(\S+)\s*(?:#.*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*admin_space_left_action\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*freq\s*=\s*(\S+)\s*(?:#.*)?$ + 1 + + + /etc/audit/auditd.conf + (?i)^\s*write_logs\s*=\s*(\w+)\s*(?:#.*)?$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/init\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/poweroff\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/reboot\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)(?:\s+-S\s+all)?\s+-F\s+path=/usr/sbin/shutdown\s+(-F\s+perm=([rwa]*x[rwa]*)\s+)?-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+umount\s+|(\s+|,)umount(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+umount2\s+|(\s+|,)umount2(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+umount2\s+|(\s+|,)umount2(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^[ \t]*-f[ \t]+2\s*$ + 1 + + + /proc/sys/crypto/fips_enabled + ^(\d+)$ + 1 + + + /etc/ipsec.conf + ^\s*include\s+(.*)\s*$ + 1 + + + /etc/ipsec.d + ^.*\.conf$ + ^\s*include\s+(.*)\s*$ + 1 + + + /etc/named.conf + ^\s*include\s+"(.*)"\s*;\s*$ + 1 + + + /etc/crypto-policies/back-ends/openssh.config + ^\s*(?i)Ciphers(?-i)[ \t]+(\S+)[\s]*(?:|(?:#.*))?$ + 1 + + + /etc/crypto-policies/back-ends/openssh.config + ^\s*MACs\s+(\S+)\s*$ + 1 + + + /etc/fapolicyd/fapolicyd.conf + ^\s*permissive\s*=\s*(\d+)\s*$ + 1 + + + + /etc/fapolicyd/compiled.rules + (.*\S.*)\s*$ + 1 + + + + oval:mil.disa.stig.ind:obj:27172001 + oval:mil.disa.stig.ind:obj:27172002 + + + + /etc/ssh/sshd_config + ^(?i)\s*PermitUserEnvironment\s+(\w+)$ + 1 + + + + /etc/ssh/sshd_config.d + ^.+\.conf$ + ^(?i)\s*PermitUserEnvironment\s+(\w+)$ + 1 + + + /etc/sudoers + ^(.*\bsysadm_r\b.*)$ + 1 + + + + /etc/sudoers.d + .* + ^(.*\bsysadm_r\b.*)$ + 1 + + + + oval:mil.disa.stig.ind:obj:27249600 + oval:mil.disa.stig.ind:obj:27249601 + + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32?\s+(?:.*(-S\s+mount\s+|(\s+|,)mount(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64?\s+(?:.*(-S\s+mount\s+|(\s+|,)mount(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32?\s+-F\s+path=/etc/sudoers\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64?\s+-F\s+path=/etc/sudoers\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32?\s+-F\s+path=/etc/group\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64?\s+-F\s+path=/etc/group\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32?\s+-F\s+path=/etc/gshadow\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64?\s+-F\s+path=/etc/gshadow\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32?\s+-F\s+path=\/etc\/security\/opasswd\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64?\s+-F\s+path=\/etc\/security\/opasswd\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32?\s+-F\s+path=/etc/passwd\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64?\s+-F\s+path=/etc/passwd\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32?\s+-F\s+path=/etc/shadow\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64?\s+-F\s+path=/etc/shadow\s+-F\s*perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)\S+)?\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+-F\s+path=\/var\/log\/faillock\s+(?:-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset))?\s*-F\s+perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+-F\s+path=\/var\/log\/faillock\s+(?:-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset))?\s*-F\s+perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\s+-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+-F\s+path=\/var\/log\/lastlog\s+(?:-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset))?\s*-F\s+perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+-F\s+path=\/var\/log\/lastlog\s+(?:-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset))?\s*-F\s+perm=([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+fchmodat2\s+|(\s+|,)fchmodat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+fchmodat2\s+|(\s+|,)fchmodat(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b32\s+(?:.*(-S\s+renameat2\s+|(\s+|,)renameat2(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc/audit/audit.rules + ^\s*-a\s+(always,exit|exit,always)\s+-F\s+arch=b64\s+(?:.*(-S\s+renameat2\s+|(\s+|,)renameat2(\s+|,))).*-F\s+auid>=1000\s+-F\s+auid!=(4294967295|-1|unset)(\s+(-k\s+|-F\s+key=)[-\w]+)*\s*$ + 1 + + + /etc + redhat-release + ^\s*Red Hat Enterprise Linux release 10\.(\d+) + 1 + + + gnome-shell + + + gnome-shell + + + /boot/efi + + + /sys/fs/selinux + + + + + + /boot + + + .*\/home + + + audit + + + rsyslog + + + rsyslog-gnutls + + + telnet-server + + + /dev/shm + + + /dev/shm + + + /tmp + + + /var/log/audit + + + /var/log/audit + + + ctrl-alt-del.target + LoadState + + + ctrl-alt-del.target + UnitFileState + + + debug-shell.service + LoadState + + + debug-shell.service + UnitFileState + + + tftp-server + + + postfix + + + /boot/efi + + + fapolicyd.service + ActiveState + + + systemd-journald.service + ActiveState + + + ftp + + + gnutls-utils + + + autofs + + + .*\/home + + + /boot + + + libreswan + + + sshd.service + ActiveState + + + openssh-clients + + + pcsc-lite + + + pcscd.socket + ActiveState + + + opensc + + + rsyslog.service + ActiveState + + + auditd.service + ActiveState + + + auditd.service + SubState + + + crypto-policies + + + bind + + + tftp + + + pcsc-lite-ccid + + + cronie + + + pkcs11-provider + + + aide + + + libreswan + + + /sys/firmware/efi + + + + net.ipv6.conf.all.disable_ipv6 + + + /etc/passwd + + + /etc/group- + + + [\w]+ + + + + oval:mil.disa.stig.unix:obj:20000016 + oval:mil.disa.stig.unix:ste:20000017 + + + + + oval:mil.disa.stig.unix:obj:20000016 + oval:mil.disa.stig.unix:ste:20000018 + + + + /var/log/messages + + + /var/log/messages + + + /var/log + + + + /var/log + + + + kernel.kexec_load_disabled + + + kernel.randomize_va_space + + + + /etc/ssh + ^.*\.pub$ + + + kernel.core_pattern + + + + + + root + + + kernel.kptr_restrict + + + /etc/sudoers.d + ^[^.]*[^.~]$ + + + fs.protected_symlinks + + + fs.protected_hardlinks + + + kernel.dmesg_restrict + + + kernel.perf_event_paranoid + + + /etc/systemd/system/default.target + + + /etc/ssh + ^ssh_host.*key$ + + + /boot/grub2/grub.cfg + + + /boot/grub2/grub.cfg + + + /etc/shadow- + + + /etc/group + + + /etc/group- + + + /etc/gshadow + + + /etc/gshadow + + + /etc + gshadow- + + + /etc/gshadow- + + + /etc/passwd- + + + /etc + shadow + + + /etc/shadow + + + /etc + shadow- + + + .* + oval:mil.disa.stig.unix:ste:25804500 + + + .+ + + + + oval:mil.disa.stig.unix:obj:25804600 + oval:mil.disa.stig.unix:ste:25804601 + oval:mil.disa.stig.unix:ste:25804602 + + + + .* + + + + + .* + oval:mil.disa.stig.unix:ste:20000005 + + + + + + /var/lib/aide/aide.db.gz + + + + + (?:^nosuid$|^nosuid,|,nosuid$|,nosuid,) + + + (?:^nosuid$|^nosuid,|,nosuid$|,nosuid,) + + + vfat + + + false + + + true + + + 0 + + + 1 + + + 2 + + + 3 + + + 4 + + + 5 + + + 6 + + + 7 + + + 8 + + + 9 + + + 10 + + + none + + + 0 + + + ^(yes|"yes")$ + + + ^(no|"no")$ + + + ^[123]$ + + + 0 + + + 0 + + + ^(True|1|yes)$ + + + (?i)^yes$ + + + 0 + + + 077 + + + 600 + + + (?i)(?:^|\n)[^#]*\btype\s*=\s*"omfwd" + + + \n\s*crypt_style\s*=\s*(\S*)\s*(\n|$) + + + sha512 + + + SHA512 + + + ^[!*] + + + ^[$][6][$] + + + \n\s*gpgcheck\s*=\s*(True|1|yes)\s*(\n|$) + + + \n\s*gpgcheck\s*=\s*(False|0|no)\s*(\n|$) + + + (^|\s)vsyscall=none(\s|$) + + + (^|\s)init_on_free=1(\s|$) + + + targeted + + + (?:^nodev$|^nodev,|,nodev$|,nodev,) + + + (^|,)noexec(,|$) + + + (^|,)nodev(,|$) + + + (^|,)nosuid(,|$) + + + 3 + + + 900 + + + /var/log/faillock + + + 4 + + + 3 + + + 4 + + + 8 + + + 15 + + + 35 + + + 4 + + + 077 + + + 077 + + + (?i)^root$ + + + (?i)^syslog$ + + + (?i)^single$ + + + (?i)^halt$ + + + (?i)^hostname$ + + + (?i)^fqd$ + + + (?i)^numeric$ + + + (?i)^enriched$ + + + (^|\s)audit=1(\s|$) + + + 25 + + + 100 + + + (^|\s)pti=on(\s|$) + + + (?:^nosuid$|^nosuid,|,nosuid$|,nosuid,) + + + (?:^noexec$|^noexec,|,noexec$|,noexec,) + + + nodev + + + nodev + + + ^.*noexec.*$ + + + ^(?i)\s*RekeyLimit\s+[1-9][0-9]*[kmg]?\s+([1-9][0-9]*[smhdw]?)+\s*$ + + + ^VERBOSE$|^"VERBOSE"$ + + + /etc/sudoers.d + + + (?i)^email$ + + + ^pam_pwquality.so(\s|$) + + + ^\S+$ + + + ^grub\.pbkdf2\.sha512\. + + + (^|\s)systemd\.confirm_spawn(\s|$) + + + (^|\s)page_poison=1(\s|$) + + + 1 + + + (^|,)sec=[^,]+(,|$) + + + (^|,)sec=([^:,]*:)?krb5[pi]?(:|,|$) + + + (^|,)sec=([^:,]*:)?sys(:|,|$) + + + ^\/.+$ + + + /etc/ssh/sshd_config.d/*.conf + + + aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr + + + "aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr" + + + hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512 + + + "hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512" + + + 600 + + + 0 + + + 60 + + + + + + + + + 100000 + + + (?i)\bcac\b + + + ^.+$ + + + (?i)(?:^|\n)[^#]*\bprotocol\s*=\s*"tcp" + + + 10737418240 + + + 5% + + + 1 + + + 100 + + + /etc/crypto-policies/back-ends/libreswan.config + + + /etc/ipsec.d/*.conf + + + /etc/crypto-policies/back-ends/bind.config + + + (?:^|\n)(?:deny|deny_log|deny_audit)[ \t]+perm=any[ \t]+all[ \t]+:[ \t]+all(?:$|\n) + + + ^[ \t]*%[a-zA-Z0-9_-]+[ \t]+ALL=\(ALL\)[ \t]+TYPE=sysadm_t[ \t]+ROLE=sysadm_r[ \t]+ALL[ \t]*$ + + + vfat + + + noexec + + + nodev + + + nosuid + + + active + + + running + + + masked + + + selinuxfs + + + nosuid + + + false + false + false + false + false + false + false + false + + + false + false + false + false + false + false + false + false + false + false + + + 0 + + + 0 + + + false + false + false + false + false + + + 1 + + + 2 + + + .+ + + + 1000 + + + 0 + + + |/bin/false + + + 0 + + + [\S]*\/multi\-user\.target$ + + + 1000 + + + /sbin/nologin|/usr/sbin/nologin + + + 1000 + + + 0 + + + + + + 0 + + + + + /etc/sysctl.d + /run/sysctl.d + /lib/sysctl.d + /usr/lib/sysctl.d + /usr/local/lib/sysctl.d + + + ^\s*-a\s+(?:always,exit|exit,always) + + + \s+-F\s+arch=b32 + + + \s+-F\s+arch=b64 + + + \s+(?:-S\s+[,\w]+\s+)* + + + -S\s+[,\w]*\b + + + \b[,\w]* + + + -F\s+auid>=1000\s+-F\s+auid!=(?:4294967295|-1|unset) + + + (?:\s+(?:-k\s+|-F\s+key=)[-\w]+)*\s*$ + + + -F\s+auid=0 + + + /bin + /sbin + /usr/bin + /usr/sbin + /usr/libexec + /usr/local/bin + /usr/local/sbin + + + + + + /sbin/auditctl + /sbin/aureport + /sbin/ausearch + /sbin/autrace + /sbin/auditd + /sbin/rsyslogd + /sbin/augenrules + + + + + + + + + + + lsetxattr + + + + + + + + + + + + + lsetxattr + + + + + + + + + + + + + lsetxattr + + + + + + + + + + + + + lsetxattr + + + + + + + + + + + + + removexattr + + + + + + + + + + + + + removexattr + + + + + + + + + + + + + removexattr + + + + + + + + + + + + + removexattr + + + + + + + + + /etc/dconf/db/ + + .d/locks + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + ^[^#]*InputTCPServerRun + ^[^#]*UDPServerRun + ^[^#]*RELPServerRun + ^[^#]*module\s*\(.*\bload\s*=\s*"imtcp".*\) + ^[^#]*module\s*\(.*\bload\s*=\s*"imudp".*\) + ^[^#]*module\s*\(.*\bload\s*=\s*"imrelp".*\) + ^[^#]*input\s*\(.*\btype\b\s*=\s*"imtcp"\s*\bport\b\s*=\s*"514".*\) + ^[^#]*input\s*\(.*\btype\b\s*=\s*"imudp"\s*\bport\b\s*=\s*"514".*\) + ^[^#]*input\s*\(.*\btype\b\s*=\s*"imrelp"\s*\bport\b\s*=\s*"514".*\) + + + + + + + + + /sbin/auditctl + /sbin/aureport + /sbin/ausearch + /sbin/auditd + /sbin/rsyslogd + /sbin/augenrules + + + + + + + + + + + + + + + + + + Security Content Tool 1.9.1 + 5.11 + 2026-08-25T11:17:20 + + + + + RHEL 10 is installed + + Red Hat Enterprise Linux 10 + + + RHEL 10 is installed + + + + + + + + + + + + + + + + + + + + + + + toss-release + + + oraclelinux-release + + + redhat-release + + + + + ^10\.\d+$ + + + + +