Item Search

NameAudit NamePluginCategory
GEN003830 - The rlogind service must not be running.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN003850 - The telnet daemon must not be running.DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN003930 - The hosts.lpd (or equivalent) file must be group-owned by root, bin, or sys - /etc/printers.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004440 - Sendmail logging must not be set to less than nine in the sendmail.cf file.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004640 - The SMTP service must not have a uudecode alias active.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004660 - The SMTP service must not have the EXPN feature active.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004710 - Mail relaying must be restricted - Postfix local onlyDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004710 - Mail relaying must be restricted - SendmailDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004800 - Unencrypted FTP must not be used on the system.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004900 - The ftpusers file must contain account names not allowed to use FTP.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN005000 - Anonymous FTP accounts must not have a functional shell.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005120 - The TFTP daemon must be configured to vendor specifications, including a dedicated TFTP user account, a non-login shell, such as /bin/false, and a home directory owned by the TFTP user - a non-login shellDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005120 - The TFTP daemon must be configured to vendor specifications, including a dedicated TFTP user account, a non-login shell, such as /bin/false, and a home directory owned by the TFTP user - dedicated TFTP accountDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005220 - .Xauthority or X*.hosts (or equivalent) file(s) must be used to restrict access to the X server.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005280 - The system must not have the UUCP service active.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /etc/snmp/conf/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005305 - The SNMP service must use only SNMPv3 or its successors - /etc/sma/snmp/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005305 - The SNMP service must use only SNMPv3 or its successors - /etc/snmp/conf/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005320 - The snmpd.conf file must have mode 0600 or less permissive - /var/sma_snmp/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN005360 - The snmpd.conf files must be owned by root - /etc/sma/snmp/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005360 - The snmpd.conf files must be owned by root - /usr/sfw/lib/sma_snmp/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005365 - The snmpd.conf file must be group-owned by root, sys, or bin - /etc/snmp/conf/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005395 - The /etc/syslog.conf file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005500 - The SSH daemon must be configured to only use the SSHv2 protocol.DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN005506 - The SSH daemon must be configured to not use Cipher-Block Chaining (CBC) ciphers.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005511 - The SSH client must be configured to not use CBC-based ciphers.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005524 - The SSH daemon must not permit GSSAPI authentication unless needed.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005539 - The SSH daemon must not allow compression or must only allow compression after successful authentication.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005540 - The SSH daemon must be configured for IP filtering.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005570 - The system must be configured with a default gateway for IPv6 if the system uses IPv6, unless the system is a router.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005580 - A system used for routing must not run other network services or applications.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005610 - The system must not have IP forwarding for IPv6 enabled, unless the system is an IPv6 router.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005860 - The system's NFS export configuration must not have the sec option set to none (or equivalent); additionally, the default authentication must not to be set to none - sec=noneDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006000 - The system must not have a public Instant Messaging (IM) client installed.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006060 - The system must not run Samba unless needed.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006080 - The Samba Web Administration Tool (SWAT) must be restricted to the local host or require SSL - hosts.allowDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006100 - The smb.conf file must be owned by root.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006180 - The smbpasswd file must be group-owned by root.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006260 - The /etc/news/hosts.nntp (or equivalent) must have mode 0600 or less permissive.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN006280 - The /etc/news/hosts.nntp.nolimit (or equivalent) must have mode 0600 or less permissive.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN006310 - The /etc/news/nnrp.access file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006360 - The files in /etc/news must be group-owned by root - /etc/news/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006380 - The system must not use UDP for NIS/NIS+.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006400 - The Network Information System (NIS) protocol must not be used.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006570 - The file integrity tool must be configured to verify ACLs - usedDISA STIG Solaris 10 SPARC v2r4Unix

SYSTEM AND INFORMATION INTEGRITY

GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents - usedDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN006580 - The system must use an access control program.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006600 - The system's access control program must log each system access attempt.DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN006620 - The system's access control program must be configured to grant or deny system access to specific hosts - default denyDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN006620 - The system's access control program must be configured to grant or deny system access to specific hosts - host.denyDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT