Item Search

NameAudit NamePluginCategory
GEN000000-SOL00060 - The /etc/security/audit_user file must be owned by root.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00100 - The /etc/security/audit_user file must have mode 0640 or less permissive.DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN000000-SOL00120 - The ASET master files must be located in the /usr/aset/masters directory - uid_aliasesDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000000-SOL00180 - The Solaris system Automated Security Enhancement Tool (ASET) configurable parameters in the asetenv file must be correct - ASET configurable parameters in the asetenv file must be correct.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

GEN000000-SOL00240 - The /usr/aset/userlist file must be owned by root.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00250 - The /usr/aset/userlist file must be group-owned by root.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00300 - The Solaris system EEPROM security-mode parameter must be set to full or command mode.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00400 - The NFS server must have logging implemented.DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN000000-SOL00580 - The /etc/zones directory, and its contents, must not be group- or world-writable - /etc/zonesDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00580 - The /etc/zones directory, and its contents, must not be group- or world-writable - /etc/zones/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00620 - The inherit-pkg-dir zone option must be set to none or the system default list defined for sparse root zones.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000220 - A file integrity tool must be used at least weekly to check for unauthorized file changes, particularly the addition of unauthorized system libraries or binaries, or for unauthorized modification to authorized system libraries or binaries.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000241 - The system clock must be synchronized continuously.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000253 - The time synchronization configuration file (such as /etc/ntp.conf) must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000290 - The system must not have unnecessary accounts.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000320 - All accounts must be assigned unique User Identification Numbers (UIDs).DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000452 - The system must display the date and time of the last successful account login upon login.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000460 - The system must disable accounts after three consecutive unsuccessful login attempts - RETRIESDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000500 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity and the system must require users to re-authenticate to unlock the environment - dtsession*lockTimeoutDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000595 - The password hashes stored on the system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm - /etc/passwdDISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000595 - The password hashes stored on the system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm - /etc/shadowDISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN000760 - Accounts must be locked upon 35 days of inactivity.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000790 - The system must prevent the use of dictionary words for passwords - DICTIONLISTDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000880 - The root account must be the only account having an UID of 0.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000930 - The root account's home directory must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000960 - The root account must not have world-writable directories in its executable search path.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001020 - The root account must not be used for direct logins - login reportDISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN001060 - The system must log successful and unsuccessful access to the root account - /var/adm/sulogDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN001080 - The root shell must be located in the / file system.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001140 - System files and directories must not have uneven access permissions - /bin/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001140 - System files and directories must not have uneven access permissions - /usr/sbin/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001200 - All system command files must have mode 755 or less permissive - /bin/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001220 - All system files, programs, and directories must be owned by a system account - /usr/sbin/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001240 - System files, programs, and directories must be group-owned by a system group - /etc/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001240 - System files, programs, and directories must be group-owned by a system group - /usr/bin/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001270 - System log files must not have extended ACLs, except as needed to support authorized software.DISA STIG Solaris 10 SPARC v2r4Unix

SYSTEM AND INFORMATION INTEGRITY

GEN001280 - Manual page files must have mode 0655 or less permissive - /usr/share/man/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN006640 - The system must use a virus scan program.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN007480 - The Reliable Datagram Sockets (RDS) protocol must be disabled or not installed unless required.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN007780 - The system must not have 6to4 enabled.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN007950 - The system must not respond to ICMPv6 echo requests sent to a broadcast address - dladm show-linkDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008120 - If the system is using LDAP for authentication or account information, the /etc/ldap.conf (or equivalent) file must not have an extended ACL - ldap_client_credDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008180 - If the system is using LDAP for authentication or account information, the TLS certificate authority file and/or directory (as appropriate) must have mode 0644 (0755 for directories) or less permissive - cert8.dbDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008180 - If the system is using LDAP for authentication or account information, the TLS certificate authority file and/or directory (as appropriate) must have mode 0644 (0755 for directories) or less permissive - key3.dbDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008180 - If the system is using LDAP for authentication or account information, the TLS certificate authority file and/or directory (as appropriate) must have mode 0644 (0755 for directories) or less permissive - secmod.dbDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008520 - The system must employ a local firewall.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008540 - The system's local firewall must implement a deny-all, allow-by-exception policy.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN008640 - The system must not use removable media as the boot loader.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

SOL-11.1-060190 - The operating system must protect the integrity of transmitted information.DISA Solaris 11 X86 STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION