Item Search

NameAudit NamePluginCategory
BIND-9X-001360 - The BIND 9.x server implementation must prohibit the forwarding of queries to servers controlled by organizations outside of the U.S. government.DISA BIND 9.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00110 - The /etc/security/audit_user file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00600 - The /etc/zones directory, and its contents, must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00660 - The physical devices must not be assigned to non-global zones.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000242 - The system must use at least two time sources for clock synchronization - service ntp server 1DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN000250 - The time synchronization configuration file (such as /etc/ntp.conf) must be owned by root.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000251 - The time synchronization configuration file (such as /etc/ntp.conf) must be group-owned by root, bin, or sys.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000400 - The Department of Defense (DoD) login banner must be displayed immediately prior to, or as part of, console login prompts.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000410 - The FTPS/FTP service on the system must be configured with the Department of Defense (DoD) login banner - banner configuredDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000440 - Successful and unsuccessful logins and logouts must be logged.DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN000500 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity and the system must require users to re-authenticate to unlock the environment - user lockDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000560 - The system must not have accounts configured with blank or null passwords.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000580 - The system must require passwords contain a minimum of 15 characters.DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000585 - The system must enforce compliance of the entire password during authentication - /etc/shadowDISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000590 - The system must use a FIPS 140-2 approved cryptographic hashing algorithm for generating account password hashes - CRYPT_ALGORITHMS_ALLOWDISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000750 - The system must require at least eight characters be changed between the old and new passwords during a password change.DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000850 - The system must restrict the ability to switch to the root user to members of a defined group - type=roleDISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000920 - The root account's home directory (other than /) must have mode 0700.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000980 - The system must prevent the root account from directly logging in except from the system console.DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN001000 - Remote consoles must be disabled or protected from unauthorized access.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001140 - System files and directories must not have uneven access permissions - /sbin/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001140 - System files and directories must not have uneven access permissions - /usr/bin/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001160 - All files and directories must have a valid owner.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001200 - All system command files must have mode 755 or less permissive - /etc/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001200 - All system command files must have mode 755 or less permissive - /usr/lbin/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001220 - All system files, programs, and directories must be owned by a system account - /etc/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001280 - Manual page files must have mode 0655 or less permissive - /usr/sfw/share/man/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001300 - Library files must have mode 0755 or less permissive - /lib/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001390 - The /etc/passwd file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001430 - The /etc/shadow file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001490 - User's home directories must not have extended ACLs.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001520 - All interactive user's home directories must be group-owned by the home directory owner's primary group.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001550 - All files and directories contained in user home directories must be group-owned by a group of which the home directory's owner is a member.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001580 - All run control scripts must have mode 0755 or less permissive - /lib/svc/method/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001605 - Run control scripts lists of preloaded libraries must contain only authorized paths - /etc/rc*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005900 - The nosuid option must be enabled on all NFS client mounts.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006225 - Samba must be configured to use an authentication mechanism other than 'share.' - share.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006230 - Samba must be configured to use encrypted passwords.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006270 - The /etc/news/hosts.nntp file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006330 - The /etc/news/passwd.nntp file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006570 - The file integrity tool must be configured to verify ACLs - configDISA STIG Solaris 10 SPARC v2r4Unix

SYSTEM AND INFORMATION INTEGRITY

GEN006571 - The file integrity tool must be configured to verify extended attributes - usedDISA STIG Solaris 10 SPARC v2r4Unix

SYSTEM AND INFORMATION INTEGRITY

GEN007840 - The DHCP client must be disabled if not needed.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN007841 - Wireless network adapters must be disabled.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

GEN007950 - The system must not respond to ICMPv6 echo requests sent to a broadcast address.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN007980 - If the system is using LDAP for authentication or account information, the system must use a TLS connection using FIPS 140-2 approved cryptographic algorithms - serversDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN008060 - If the system is using LDAP for authentication or account information the LDAP client configuration file must have mode 0600 or less permissive - /var/ldap/ldap_client_credDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008160 - If the system is using LDAP for authentication or account information, the TLS certificate authority file and/or directory (as appropriate) must be group-owned by root, bin, or sys - cert8.dbDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008160 - If the system is using LDAP for authentication or account information, the TLS certificate authority file and/or directory (as appropriate) must be group-owned by root, bin, or sys - key3.dbDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008820 - The system package management tool must not automatically obtain updates - /var/spool/cron/crontabs/*DISA STIG Solaris 10 SPARC v2r4Unix

SYSTEM AND INFORMATION INTEGRITY