DISA SLES 12 STIG v2r9

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA SLES 12 STIG v2r9

Updated: 9/19/2023

Authority: DISA STIG

Plugin: Unix

Revision: 1.5

Estimated Item Count: 284

Audit Changelog

 
Revision 1.5

Sep 19, 2023

Functional Update
  • SLES-12-010400 - There must be no .shosts files on the SUSE operating system.
  • SLES-12-010410 - There must be no shosts.equiv files on the SUSE operating system.
  • SLES-12-010460 - The sticky bit must be set on all SUSE operating system world-writable directories.
  • SLES-12-010690 - All SUSE operating system files and directories must have a valid owner.
  • SLES-12-010700 - All SUSE operating system files and directories must have a valid group owner.
  • SLES-12-010780 - All SUSE operating system local initialization files must not execute world-writable programs.
  • SLES-12-010830 - All SUSE operating system world-writable directories must be group-owned by root, sys, bin, or an application group.
  • SLES-12-010871 - The SUSE operating system library files must have mode 0755 or less permissive.
  • SLES-12-010872 - The SUSE operating system library directories must have mode 0755 or less permissive.
  • SLES-12-010873 - The SUSE operating system library files must be owned by root.
  • SLES-12-010874 - The SUSE operating system library directories must be owned by root.
  • SLES-12-010875 - The SUSE operating system library files must be group-owned by root.
  • SLES-12-010876 - The SUSE operating system library directories must be group-owned by root.
  • SLES-12-010877 - The SUSE operating system must have system commands set to a mode of 0755 or less permissive.
  • SLES-12-010878 - The SUSE operating system must have directories that contain system commands set to a mode of 0755 or less permissive.
  • SLES-12-010879 - The SUSE operating system must have system commands owned by root.
  • SLES-12-010881 - The SUSE operating system must have directories that contain system commands owned by root.
  • SLES-12-010882 - The SUSE operating system must have system commands group-owned by root or a system account.
  • SLES-12-010883 - The SUSE operating system must have directories that contain system commands group-owned by root.
  • SLES-12-010910 - The SUSE operating system must be configured to not overwrite Pluggable Authentication Modules (PAM) configuration on package changes.
Miscellaneous
  • Variables updated.
Revision 1.4

Aug 29, 2023

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.3

May 16, 2023

Miscellaneous
  • Metadata updated.
Revision 1.2

Apr 12, 2023

Functional Update
  • SLES-12-010140 - The SUSE operating system must enforce a delay of at least four (4) seconds between logon prompts following a failed logon attempt.
  • SLES-12-010210 - The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).
  • SLES-12-010240 - The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords - SHA_CRYPT_MIN_ROUNDS
  • SLES-12-010260 - The SUSE operating system must be configured to create or update passwords with a minimum lifetime of 24 hours (one day) - 1 day.
  • SLES-12-010280 - The SUSE operating system must be configured to create or update passwords with a maximum lifetime of 60 days.
  • SLES-12-010620 - The SUSE operating system default permissions must be defined in such a way that all authenticated users can only read and modify their own files.
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.
Revision 1.1

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.