Item Search

NameAudit NamePluginCategory
RHEL-10-000510 - RHEL 10 must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information on local disk partitions that requires at-rest protection.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-001020 - RHEL 10 must ensure cryptographic verification of vendor software packages.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200000 - RHEL 10 must remove all software components after updated versions have been installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-200060 - RHEL 10 must not have the unbound package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200080 - RHEL 10 must not have the "gdm" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200520 - RHEL 10 must have the "s-nail" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200540 - RHEL 10 must have the "chrony" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200562 - RHEL 10 must block unauthorized peripherals before establishing a connection.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200563 - RHEL 10 must enable audit logging for the USBGuard daemon.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200600 - RHEL 10 must have the "fapolicy" module installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200621 - RHEL 10 must use the common access card (CAC) smart card driver.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200660 - RHEL 10 must have the "audit" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-200680 - RHEL 10 must have the "libreswan" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200730 - RHEL 10 must have the "pkcs11-provider" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-300030 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-300070 - RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400025 - RHEL 10 must be configured so that the "/etc/gshadow" file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400035 - RHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400045 - RHEL 10 must be configured so that the "/etc/passwd" file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400090 - RHEL 10 must be configured so that the "/var/log/"messages file is owned by root.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-400145 - RHEL 10 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400150 - RHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400195 - RHEL 10 must enforce root ownership of the "/etc/audit/" directory.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-400240 - RHEL 10 must enforce mode "0750" or less permissive for local interactive user home directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400315 - RHEL 10 must define default permissions for the bash shell.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400330 - RHEL 10 must define default permissions for the system default profile.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400340 - RHEL 10 must enforce mode "0600" or less permissive for Secure Shell (SSH) private host key files.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400355 - RHEL 10 must prevent device files from being interpreted on file systems that contain user home directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-400410 - RHEL 10 must mount "/var/log/audit" with the "nosuid" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-500360 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "semanage" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500390 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500430 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chsh" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500740 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-600100 - RHEL 10 must, for new users or password changes, have a 60-day maximum password lifetime restriction for user account passwords in "/etc/login.defs".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600120 - RHEL 10 must assign a home directory for local interactive user accounts upon creation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-600130 - RHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600210 - RHEL 10 must enforce a 24-hours minimum password lifetime restriction for passwords for new users or password changes in "/etc/login.defs".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600270 - RHEL 10 must enforce that passwords have a 24 hours/1 day minimum lifetime restriction in "/etc/shadow".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600280 - RHEL 10 must require the maximum number of repeating characters of the same character class to be limited to four when passwords are changed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600300 - RHEL 10 must require the change of at least four character classes when passwords are changed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600410 - RHEL 10 must automatically lock an account when three unsuccessful login attempts occur.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600475 - RHEL 10 must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600520 - RHEL 10 must restrict privilege elevation to authorized personnel.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-600560 - RHEL 10 must require users to provide a password for privilege escalation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600620 - RHEL 10 must ensure the password complexity module is enabled in the "password-auth" file.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600740 - RHEL 10 must be configured to use the shadow file to store only encrypted representations of passwords.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700140 - RHEL 10 must mount "/dev/shm" with the "noexec" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700155 - RHEL 10 must mount "/tmp" with the "noexec" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-800240 - RHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800300 - RHEL 10 must configure a DNS processing mode in Network Manager to avoid conflicts with other Domain Name Server (DNS) managers and to not leak DNS queries to untrusted networks.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION