Item Search

NameAudit NamePluginCategory
SLES-12-010020 - The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner until users acknowledge the usage conditions and take explicit actions to log on for further access to the local graphical user interface.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010050 - The SUSE operating system must display the approved Standard Mandatory DoD Notice before granting local or remote access to the system via a graphical user logon.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010070 - The SUSE operating system must utilize vlock to allow for session locking.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010100 - The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010110 - The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010111 - The SUSE operating system must restrict privilege elevation to authorized personnel.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010113 - The SUSE operating system must require re-authentication when using the 'sudo' command - sudo command.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010114 - The SUSE operating system must not be configured to bypass password requirements for privilege escalation.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010120 - The SUSE operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010140 - The SUSE operating system must enforce a delay of at least four (4) seconds between logon prompts following a failed logon attempt.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010220 - The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010221 - The SUSE operating system must not have accounts configured with blank or null passwords.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010280 - The SUSE operating system must be configured to create or update passwords with a maximum lifetime of 60 days.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010331 - The SUSE operating system must automatically expire temporary accounts within 72 hours.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010375 - The SUSE operating system must restrict access to the kernel message buffer.DISA SLES 12 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-010520 - The SUSE operating system file integrity tool must be configured to verify Access Control Lists (ACLs).DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010620 - The SUSE operating system default permissions must be defined in such a way that all authenticated users can only read and modify their own files.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010630 - The SUSE operating system must not have unnecessary accounts.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010650 - The SUSE operating system root account must be the only account having unrestricted access to the system.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010680 - The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to prohibit the use of cached offline authentications after one day.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010730 - All SUSE operating system local interactive user home directories defined in the /etc/passwd file must exist.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010740 - All SUSE operating system local interactive user home directories must have mode 0750 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010760 - All SUSE operating system local initialization files must have mode 0740 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010770 - All SUSE operating system local interactive user initialization files executable search paths must contain only paths that resolve to the users home directory.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010790 - SUSE operating system file systems that contain user home directories must be mounted to prevent files with the setuid and setgid bit set from being executed.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010810 - SUSE operating system file systems that are being imported via Network File System (NFS) must be mounted to prevent files with the setuid and setgid bit set from being executed.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010820 - SUSE operating system file systems that are being imported via Network File System (NFS) must be mounted to prevent binary files from being executed.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010860 - The SUSE operating system must use a separate file system for /var.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010872 - The SUSE operating system library directories must have mode 0755 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010875 - The SUSE operating system library files must be group-owned by root.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010878 - The SUSE operating system must have directories that contain system commands set to a mode of 0755 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010882 - The SUSE operating system must have system commands group-owned by root or a system account.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-020000 - The SUSE operating system must have the auditing package installed.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

SLES-12-020020 - The SUSE operating system must allocate audit record storage capacity to store at least one weeks worth of audit records when audit records are not immediately sent to a central audit record storage facility.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020199 - The SUSE operating system must not disable syscall auditing.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-020210 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-12-020250 - The SUSE operating system must generate audit records for all uses of the su command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020310 - The SUSE operating system must generate audit records for all uses of the ssh-agent command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020411 - The SUSE operating system must generate audit records for all uses of the unlink, unlinkat, rename, renameat and rmdir syscalls.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020580 - The SUSE operating system must generate audit records for a uses of the chsh command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020620 - The SUSE operating system must generate audit records for all uses of the chacl command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-030011 - The SUSE operating system must not have the vsftpd package installed if not required for operational support.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SLES-12-030020 - The SUSE operating system file /etc/gdm/banner must contain the Standard Mandatory DoD Notice and Consent banner text.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-030030 - The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT

SLES-12-030151 - The SUSE operating system must not allow users to override SSH environment variables.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030240 - The SUSE operating system SSH daemon must use privilege separation.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030330 - Address space layout randomization (ASLR) must be implemented by the SUSE operating system to protect memory from unauthorized code execution.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-12-030400 - The SUSE operating system must not allow interfaces to accept Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030420 - The SUSE operating system must not send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirects.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030530 - The SUSE operating system, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION