Revision 1.5

Apr 12, 2023
Functional Update
  • OL08-00-010110 - OL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
  • OL08-00-010130 - The OL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.
  • OL08-00-010291 - The OL 8 SSH server must be configured to use only ciphers employing FIPS 140-2 validated cryptographic algorithms.
  • OL08-00-010571 - OL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
  • OL08-00-010760 - All OL 8 local interactive user accounts must be assigned a home directory upon creation.
  • OL08-00-020190 - OL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in '/etc/login.defs'.
  • OL08-00-020200 - OL 8 user account passwords must have a 60-day maximum password lifetime restriction.
  • OL08-00-020231 - OL 8 passwords for new users must have a minimum of 15 characters.
  • OL08-00-020310 - OL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
  • OL08-00-020351 - OL 8 default permissions must be defined in such a way that all authenticated users can read and modify only their own files.
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.