Item Search

NameAudit NamePluginCategory
OL08-00-010183 - OL 8 cryptographic policy must not be overridden.DISA Oracle Linux 8 STIG v2r8Unix

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010186 - OL 8 IP tunnels must use FIPS 140-3-approved cryptographic algorithms.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010201 - OL 8 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010230 - The OL 8 "/var/log/messages" file must be group-owned by root.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010290 - The OL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, MAINTENANCE

OL08-00-010291 - The OL 8 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, MAINTENANCE

OL08-00-010330 - OL 8 library files must have mode 755 or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010331 - OL 8 library directories must have mode 755 or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010341 - OL 8 library directories must be owned by root.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010350 - OL 8 library files must be group-owned by root.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010371 - OL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010372 - OL 8 must prevent the loading of a new kernel for later execution.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010381 - OL 8 must require users to reauthenticate for privilege escalation and changing roles.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010382 - OL 8 must restrict privilege elevation to authorized personnel.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010421 - OL 8 must clear the page allocator to prevent use-after-free attacks.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010422 - OL 8 must disable virtual syscalls.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010440 - YUM must remove all software components after updated versions have been installed on OL 8.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010472 - OL 8 must have the packages required to use the hardware random number generator entropy gatherer service.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010521 - The OL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010544 - OL 8 must use a separate file system for /var/tmp.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010760 - All OL 8 local interactive user accounts must be assigned a home directory upon creation.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010800 - A separate OL 8 filesystem must be used for user home directories (such as "/home" or an equivalent).DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010820 - Unattended or automatic logon via the OL 8 graphical user interface must not be allowed.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020026 - OL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020040 - OL 8 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-020043 - OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for command line sessions.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020080 - OL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020090 - OL 8 must map the authenticated identity to the user or group account for PKI-based authentication.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020101 - OL 8 must ensure the password complexity module is enabled in the system-auth file.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020104 - OL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020140 - OL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020170 - OL 8 must require the change of at least eight characters when passwords are changed.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020263 - The OL 8 lastlog command must be owned by root.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-020300 - OL 8 must prevent the use of dictionary words for passwords.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020330 - OL 8 must not allow accounts configured with blank or null passwords.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020332 - OL 8 must not allow blank or null passwords in the password-auth file.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020351 - OL 8 default permissions must be defined in such a way that all authenticated users can read and modify only their own files.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-030020 - The OL 8 System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030040 - The OL 8 System must take appropriate action when an audit processing failure occurs.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030060 - The OL 8 audit system must take appropriate action when the audit storage volume is full.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030062 - OL 8 must label all offloaded audit logs before sending them to the central log server.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030122 - The OL 8 audit system must protect logon UIDs from unauthorized change.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030170 - OL 8 must generate audit records for all account creation events that affect "/etc/group".DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030300 - OL 8 must generate audit records for any use of the "mount" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030313 - OL 8 must generate audit records for any use of the "semanage" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030340 - OL 8 must generate audit records for any use of the "pam_timestamp_check" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030390 - OL 8 must generate audit records for any use of the delete_module syscall.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030490 - OL 8 must generate audit records for any use of the "chmod", "fchmod", and "fchmodat" system calls.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030550 - OL 8 must generate audit records for any use of the "sudo" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030560 - OL 8 must generate audit records for any use of the "usermod" command.DISA Oracle Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE