Revision 1.9Oct 31, 2025
Functional Update
- 1.1.2.1.2 Ensure nodev option set on /tmp partition
- 1.1.2.2.1 Ensure /dev/shm is a separate partition
- 1.1.2.2.2 Ensure nodev option set on /dev/shm partition
- 1.1.2.2.3 Ensure nosuid option set on /dev/shm partition
- 1.1.2.2.4 Ensure noexec option set on /dev/shm partition
- 3.4.2.4 Ensure network interfaces are assigned to appropriate zone
- 4.2.1 Ensure permissions on /etc/ssh/sshd_config are configured
- 4.2.10 Ensure sshd HostbasedAuthentication is disabled
- 4.2.11 Ensure sshd IgnoreRhosts is enabled
- 4.2.12 Ensure sshd KexAlgorithms is configured
- 4.2.13 Ensure sshd LoginGraceTime is configured
- 4.2.14 Ensure sshd LogLevel is configured
- 4.2.15 Ensure sshd MACs are configured
- 4.2.16 Ensure sshd MaxAuthTries is configured
- 4.2.17 Ensure sshd MaxSessions is configured
- 4.2.18 Ensure sshd MaxStartups is configured
- 4.2.19 Ensure sshd PermitEmptyPasswords is disabled
- 4.2.2 Ensure permissions on SSH private host key files are configured
- 4.2.20 Ensure sshd PermitRootLogin is disabled
- 4.2.21 Ensure sshd PermitUserEnvironment is disabled
- 4.2.22 Ensure sshd UsePAM is enabled
- 4.2.3 Ensure permissions on SSH public host key files are configured
- 4.2.4 Ensure sshd access is configured
- 4.2.5 Ensure sshd Banner is configured
- 4.2.6 Ensure sshd Ciphers are configured
- 4.2.7 Ensure sshd ClientAliveInterval and ClientAliveCountMax are configured
- 4.2.8 Ensure sshd DisableForwarding is enabled
- 4.2.9 Ensure sshd GSSAPIAuthentication is disabled
- 4.3.5 Ensure re-authentication for privilege escalation is not disabled globally
- 4.5.2.1 Ensure default group for the root account is GID 0
- 5.1.3 Ensure logrotate is configured
- CIS_Red_Hat_Enterprise_Linux_7_v4.0.0_L1_Workstation.audit from CIS Red Hat Enterprise Linux 7 Benchmark v4.0.0
Miscellaneous
- Metadata updated.
- Platform check updated.
- References updated.
- Variables updated.