| RHEL-10-000510 - RHEL 10 must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information on local disk partitions that requires at-rest protection. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-001020 - RHEL 10 must ensure cryptographic verification of vendor software packages. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200000 - RHEL 10 must remove all software components after updated versions have been installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-200060 - RHEL 10 must not have the unbound package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200080 - RHEL 10 must not have the "gdm" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200520 - RHEL 10 must have the "s-nail" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200540 - RHEL 10 must have the "chrony" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-200562 - RHEL 10 must block unauthorized peripherals before establishing a connection. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-200563 - RHEL 10 must enable audit logging for the USBGuard daemon. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-200600 - RHEL 10 must have the "fapolicy" module installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200621 - RHEL 10 must use the common access card (CAC) smart card driver. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-200660 - RHEL 10 must have the "audit" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| RHEL-10-200680 - RHEL 10 must have the "libreswan" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-200730 - RHEL 10 must have the "pkcs11-provider" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-300030 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-300070 - RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400025 - RHEL 10 must be configured so that the "/etc/gshadow" file is group-owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400035 - RHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400045 - RHEL 10 must be configured so that the "/etc/passwd" file is group-owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400090 - RHEL 10 must be configured so that the "/var/log/"messages file is owned by root. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-400145 - RHEL 10 must be configured so that all system device files are correctly labeled to prevent unauthorized modification. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400150 - RHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is group-owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400195 - RHEL 10 must enforce root ownership of the "/etc/audit/" directory. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-400240 - RHEL 10 must enforce mode "0750" or less permissive for local interactive user home directories. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400315 - RHEL 10 must define default permissions for the bash shell. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400330 - RHEL 10 must define default permissions for the system default profile. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400340 - RHEL 10 must enforce mode "0600" or less permissive for Secure Shell (SSH) private host key files. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400355 - RHEL 10 must prevent device files from being interpreted on file systems that contain user home directories. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-400410 - RHEL 10 must mount "/var/log/audit" with the "nosuid" option. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-500360 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "semanage" command. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| RHEL-10-500390 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| RHEL-10-500430 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chsh" command. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| RHEL-10-500740 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| RHEL-10-600100 - RHEL 10 must, for new users or password changes, have a 60-day maximum password lifetime restriction for user account passwords in "/etc/login.defs". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600120 - RHEL 10 must assign a home directory for local interactive user accounts upon creation. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-600130 - RHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600210 - RHEL 10 must enforce a 24-hours minimum password lifetime restriction for passwords for new users or password changes in "/etc/login.defs". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600270 - RHEL 10 must enforce that passwords have a 24 hours/1 day minimum lifetime restriction in "/etc/shadow". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600280 - RHEL 10 must require the maximum number of repeating characters of the same character class to be limited to four when passwords are changed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600300 - RHEL 10 must require the change of at least four character classes when passwords are changed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600410 - RHEL 10 must automatically lock an account when three unsuccessful login attempts occur. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-600475 - RHEL 10 must limit the number of concurrent sessions to 10 for all accounts and/or account types. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-600520 - RHEL 10 must restrict privilege elevation to authorized personnel. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-600560 - RHEL 10 must require users to provide a password for privilege escalation. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600620 - RHEL 10 must ensure the password complexity module is enabled in the "password-auth" file. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-600740 - RHEL 10 must be configured to use the shadow file to store only encrypted representations of passwords. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-700140 - RHEL 10 must mount "/dev/shm" with the "noexec" option. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-700155 - RHEL 10 must mount "/tmp" with the "noexec" option. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-800240 - RHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800300 - RHEL 10 must configure a DNS processing mode in Network Manager to avoid conflicts with other Domain Name Server (DNS) managers and to not leak DNS queries to untrusted networks. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |