Item Search

NameAudit NamePluginCategory
RHEL-08-010100 - RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-08-010121 - The RHEL 8 operating system must not have accounts configured with blank or null passwords.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010141 - RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-08-010160 - The RHEL 8 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-08-010190 - A sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-010200 - RHEL 8 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-010220 - The RHEL 8 /var/log/messages file must be owned by root.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-08-010260 - The RHEL 8 /var/log directory must be group-owned by root.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-08-010291 - The RHEL 8 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-08-010340 - RHEL 8 library files must be owned by root.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010358 - RHEL 8 must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010380 - RHEL 8 must require users to provide a password for privilege escalation.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-08-010383 - RHEL 8 must use the invoking user's password for privilege escalation when using "sudo".DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-08-010420 - RHEL 8 must implement non-executable data to protect its memory from unauthorized code execution.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-08-010421 - RHEL 8 must clear the page allocator to prevent use-after-free attacks.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-010460 - There must be no shosts.equiv files on the RHEL 8 operating system.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010472 - RHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010522 - The RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010540 - RHEL 8 must use a separate file system for /var.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010541 - RHEL 8 must use a separate file system for /var/log.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010542 - RHEL 8 must use a separate file system for the system audit data path.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010590 - RHEL 8 must prevent code from being executed on file systems that contain user home directories.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010630 - RHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS).DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010671 - RHEL 8 must disable the kernel.core_pattern.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010770 - All RHEL 8 local initialization files must have mode 0740 or less permissive.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010790 - All RHEL 8 local files and directories must have a valid group owner.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-10-700020 - RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user login.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700110 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via Network File System (NFS).DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700150 - RHEL 10 must mount "/tmp" with the "nodev" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700180 - RHEL 10 must mount "/var/log" with the "nosuid" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700190 - RHEL 10 must mount "/var/tmp" with the "noexec" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700690 - RHEL 10 must not have any ".shosts" files on the system.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700710 - RHEL 10 must prevent a user from overriding the disabling of the graphical user interface autorun function.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700760 - RHEL 10 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-701000 - RHEL 10 must clear the page allocator to prevent use-after-free attacks.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701030 - RHEL 10 must restrict access to the kernel message buffer.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701040 - RHEL 10 must prevent kernel profiling by nonprivileged users.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701050 - RHEL 10 must prevent the loading of a new kernel for later execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-701140 - RHEL 10 must restrict usage of ptrace to descendant processes.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701200 - RHEL 10 must disable the kdump service.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701210 - RHEL 10 must disable file system automount function unless required.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-701250 - RHEL 10 must require authentication to access emergency mode.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-701260 - RHEL 10 must require authentication to access single-user mode.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-800010 - RHEL 10 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-800190 - RHEL 10 must not send Internet Control Message Protocol (ICMP) redirects.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800200 - RHEL 10 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800210 - RHEL 10 must not enable Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800220 - RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800290 - RHEL 10 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring that rate-limiting measures on impacted network interfaces are implemented.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-900100 - RHEL 10 must prevent unauthorized changes to the audit system.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY