DISA Canonical Ubuntu 22.04 LTS STIG v2r3

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA Canonical Ubuntu 22.04 LTS STIG v2r3

Updated: 6/11/2025

Authority: DISA STIG

Plugin: Unix

Revision: 1.1

Estimated Item Count: 180

File Details

Filename: DISA_Canonical_Ubuntu_22.04_LTS_STIG_v2r3.audit

Size: 416 kB

MD5: bd4fca5a9fa54596cc708c51eb06d99e
SHA256: 403053bd4e615559ece2e30d3427460162d5c3c0d82955f5ffc8f5d697853d71

Audit Changelog

 
Revision 1.1

Jun 11, 2025

Functional Update
  • UBTU-22-255050 - Ubuntu 22.04 LTS must configure the SSH daemon to use FIPS 140-3-approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
  • UBTU-22-255055 - Ubuntu 22.04 LTS must configure the SSH daemon to use Message Authentication Codes (MACs) employing FIPS 140-3-approved cryptographic hashes to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.
  • UBTU-22-411045 - Ubuntu 22.04 LTS must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts have been made.
  • UBTU-22-412010 - Ubuntu 22.04 LTS must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
  • UBTU-22-611045 - Ubuntu 22.04 LTS must be configured so that when passwords are changed or new passwords are established, pwquality must be used.
  • UBTU-22-611055 - Ubuntu 22.04 LTS must store only encrypted representations of passwords.
  • UBTU-22-612025 - Ubuntu 22.04 LTS must electronically verify personal identity verification (PIV) credentials.
  • UBTU-22-612030 - Ubuntu 22.04 LTS, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
  • UBTU-22-631015 - Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.
  • UBTU-22-653045 - Ubuntu 22.04 LTS must be configured so that audit log files are not read- or write-accessible by unauthorized users.
  • UBTU-22-653050 - Ubuntu 22.04 LTS must be configured to permit only authorized users ownership of the audit log files.
  • UBTU-22-653060 - Ubuntu 22.04 LTS must be configured so that the audit log directory is not write-accessible by unauthorized users.
Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
  • Variables updated.