| Jul 23, 2024 MiscellaneousAudit deprecated.Metadata updated.References updated.
 | 
| Jul 19, 2024 Functional Update5.6.2 Ensure system accounts are secured
 | 
| Jul 9, 2024 Functional Update5.1.9 Ensure at is restricted to authorized users
 | 
| Jun 17, 2024 | 
| Jun 6, 2024 MiscellaneousMetadata updated.References updated.Variables updated.
Added1.1.2.1 Ensure /tmp is a separate partition1.2.1 Ensure GPG keys are configured1.2.2 Ensure gpgcheck is globally activated1.3.2 Ensure filesystem integrity is regularly checked1.3.3 Ensure cryptographic mechanisms are used to protect the integrity of audit tools1.4.2 Ensure permissions on bootloader config are configured1.6.1.3 Ensure SELinux policy is configured1.6.1.4 Ensure the SELinux mode is not disabled2.1.2 Ensure chrony is configured2.2.16 Ensure nfs-utils is not installed or the  nfs-server service is masked2.2.17 Ensure rpcbind is not installed or the  rpcbind services are masked2.2.8 Ensure a web server is not installed2.2.9 Ensure IMAP and POP3 server is not installed3.2.2 Ensure packet redirect sending is disabled3.3.1 Ensure source routed packets are not accepted3.3.2 Ensure ICMP redirects are not accepted3.3.3 Ensure secure ICMP redirects are not accepted3.3.4 Ensure suspicious packets are logged3.3.7 Ensure Reverse Path Filtering is enabled3.3.9 Ensure IPv6 router advertisements are not accepted3.4.1.1 Ensure nftables is installed3.4.1.2 Ensure a single firewall configuration utility is in use3.4.2.1 Ensure firewalld default zone is set3.4.2.2 Ensure at least one nftables table exists3.4.2.3 Ensure nftables base chains exist3.4.2.4 Ensure host based firewall loopback traffic is configured3.4.2.5 Ensure firewalld drops unnecessary services and ports3.4.2.6 Ensure nftables established connections are configured3.4.2.7 Ensure nftables default deny firewall policy5.2.10 Ensure SSH PermitUserEnvironment is disabled5.2.11 Ensure SSH IgnoreRhosts is enabled5.2.16 Ensure SSH MaxAuthTries is set to 4 or less5.2.17 Ensure SSH MaxStartups is configured5.2.18 Ensure SSH MaxSessions is set to 10 or less5.2.19 Ensure SSH LoginGraceTime is set to one minute or less5.2.20 Ensure SSH Idle Timeout Interval is configured5.2.4 Ensure SSH access is limited5.2.5 Ensure SSH LogLevel is appropriate5.2.6 Ensure SSH PAM is enabled5.2.7 Ensure SSH root login is disabled5.2.8 Ensure SSH HostbasedAuthentication is disabled5.2.9 Ensure SSH PermitEmptyPasswords is disabled5.4.2 Ensure authselect includes with-faillock5.5.1 Ensure password creation requirements are configured5.5.2 Ensure lockout for failed password attempts is configured5.5.4 Ensure password hashing algorithm is SHA-512 or yescrypt5.6.1.1 Ensure password expiration is 365 days or less5.6.1.2 Ensure minimum days between password changes is  configured5.6.1.3 Ensure password expiration warning days is 7 or more5.6.1.4 Ensure inactive password lock is 30 days or less5.6.2 Ensure system accounts are secured5.6.5 Ensure default user umask is 027 or more restrictive
 | 
| Apr 22, 2024 Functional Update4.2.1.6 Ensure rsyslog is configured to send logs to a remote log host
 | 
| Mar 18, 2024 Functional Update3.1.2 Ensure wireless interfaces are disabled5.2.2 Ensure permissions on SSH private host key files are configured5.2.3 Ensure permissions on SSH public host key files are configured
Added4.2.3 Ensure all logfiles have appropriate permissions and ownership
Removed4.2.3 Ensure all logfiles have appropriate access configured
 | 
| Feb 14, 2024 Added3.4.1.1 Ensure nftables is installed - firewall misconfigured3.4.1.1 Ensure nftables is installed - firewalld3.4.1.1 Ensure nftables is installed - nftables3.4.1.2 Ensure a single firewall configuration utility is in use - firewall misconfigured3.4.1.2 Ensure a single firewall configuration utility is in use - firewalld3.4.1.2 Ensure a single firewall configuration utility is in use - nftables3.4.2.1 Ensure firewalld default zone is set - firewall misconfigured3.4.2.1 Ensure firewalld default zone is set - firewalld3.4.2.1 Ensure firewalld default zone is set - nftables3.4.2.2 Ensure at least one nftables table exists - firewall misconfigured3.4.2.2 Ensure at least one nftables table exists - firewalld3.4.2.2 Ensure at least one nftables table exists - nftables3.4.2.3 Ensure nftables base chains exist - firewall misconfigured3.4.2.3 Ensure nftables base chains exist - firewalld3.4.2.3 Ensure nftables base chains exist - nftables3.4.2.4 Ensure host based firewall loopback traffic is configured - firewall misconfigured3.4.2.4 Ensure host based firewall loopback traffic is configured - firewalld3.4.2.4 Ensure host based firewall loopback traffic is configured - nftables3.4.2.5 Ensure firewalld drops unnecessary services and ports - firewall misconfigured3.4.2.5 Ensure firewalld drops unnecessary services and ports - firewalld3.4.2.5 Ensure firewalld drops unnecessary services and ports - nftables3.4.2.6 Ensure nftables established connections are configured - firewall misconfigured3.4.2.6 Ensure nftables established connections are configured - firewalld3.4.2.6 Ensure nftables established connections are configured - nftables3.4.2.7 Ensure nftables default deny firewall policy - firewall misconfigured3.4.2.7 Ensure nftables default deny firewall policy - firewalld3.4.2.7 Ensure nftables default deny firewall policy - nftables
Removed3.4.1.1 Ensure nftables is installed3.4.1.2 Ensure a single firewall configuration utility is in use3.4.2.1 Ensure firewalld default zone is set3.4.2.2 Ensure at least one nftables table exists3.4.2.3 Ensure nftables base chains exist - hook forward3.4.2.3 Ensure nftables base chains exist - hook input3.4.2.3 Ensure nftables base chains exist - hook output3.4.2.4 Ensure host based firewall loopback traffic is configured3.4.2.5 Ensure firewalld drops unnecessary services and ports3.4.2.6 Ensure nftables established connections are configured3.4.2.7 Ensure nftables default deny firewall policy - hook forward3.4.2.7 Ensure nftables default deny firewall policy - hook input
 | 
| Feb 5, 2024 Functional Update5.2.20 Ensure SSH Idle Timeout Interval is configured - ClientAliveCountMax sshd output
 | 
| Jan 22, 2024 Functional Update5.2.20 Ensure SSH Idle Timeout Interval is configured - ClientAliveCountMax sshd output
 |