Revision 1.5

Apr 3, 2023
Functional Update
  • RHEL-07-010483 - Red Hat Enterprise Linux operating systems version 7.2 or newer booted with a BIOS must have a unique name for the grub superusers account when booting into single-user and maintenance modes.
  • RHEL-07-020023 - The Red Hat Enterprise Linux operating system must elevate the SELinux context when an administrator calls the sudo command.
  • RHEL-07-020111 - The Red Hat Enterprise Linux operating system must disable the graphical user interface automounter unless required - automount
  • RHEL-07-020111 - The Red Hat Enterprise Linux operating system must disable the graphical user interface automounter unless required - automount-open
  • RHEL-07-020111 - The Red Hat Enterprise Linux operating system must disable the graphical user interface automounter unless required - automount-open=false
  • RHEL-07-020111 - The Red Hat Enterprise Linux operating system must disable the graphical user interface automounter unless required - automount=false
  • RHEL-07-020111 - The Red Hat Enterprise Linux operating system must disable the graphical user interface automounter unless required - autorun-never
  • RHEL-07-020111 - The Red Hat Enterprise Linux operating system must disable the graphical user interface automounter unless required - autorun-never=true
  • RHEL-07-020630 - The Red Hat Enterprise Linux operating system must be configured so that all local interactive user home directories have mode 0750 or less permissive.
  • RHEL-07-021040 - The Red Hat Enterprise Linux operating system must set the umask value to 077 for all local interactive user accounts.
  • RHEL-07-021300 - The Red Hat Enterprise Linux operating system must disable Kernel core dumps unless needed.
  • RHEL-07-030630 - The Red Hat Enterprise Linux operating system must audit all uses of the passwd command.
  • RHEL-07-030640 - The Red Hat Enterprise Linux operating system must audit all uses of the unix_chkpwd command.
  • RHEL-07-040160 - The Red Hat Enterprise Linux operating system must be configured so that all network connections associated with a communication session are terminated at the end of the session or after 15 minutes of inactivity from the user at a command prompt, except to fulfill documented and validated mission requirements.