Item Search

NameAudit NamePluginCategory
RHEL-09-232145 - RHEL 9 /etc/passwd- file must be group-owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-232155 - RHEL 9 /etc/shadow file must be group-owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-232190 - RHEL 9 system commands must be owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-232220 - RHEL 9 audit tools must be owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-232230 - RHEL 9 cron configuration files directory must be owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-232250 - All RHEL 9 local files and directories must have a valid group owner.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-232270 - RHEL 9 /etc/shadow file must have mode 0000 to prevent unauthorized access.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-251020 - The RHEL 9 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-252025 - RHEL 9 must disable the chrony daemon from acting as a server.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-252040 - RHEL 9 must configure a DNS processing mode in Network Manager.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-252050 - RHEL 9 must be configured to prevent unrestricted mail relaying.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-253040 - RHEL 9 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-253055 - RHEL 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-254030 - RHEL 9 must not accept router advertisements on all IPv6 interfaces by default.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-254035 - RHEL 9 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-255045 - RHEL 9 must not permit direct logons to the root account using remote access via SSH.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-255070 - The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-255075 - The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-271010 - RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-271020 - RHEL 9 must disable the graphical user interface automount function unless required.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-271040 - RHEL 9 must not allow unattended or automatic logon via the graphical user interface.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-271045 - RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-291010 - RHEL 9 must be configured to disable USB mass storage.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-291040 - RHEL 9 wireless network adapters must be disabled.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-411015 - RHEL 9 user account passwords must have a 60-day maximum password lifetime restriction.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-411025 - RHEL 9 must set the umask value to 077 for all local interactive user accounts.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-411070 - All RHEL 9 local interactive user home directories must be group-owned by the home directory owner's primary group.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-411075 - RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-411090 - RHEL 9 must maintain an account lock until the locked account is released by an administrator.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-411110 - RHEL 9 groups must have unique Group ID (GID).DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-412060 - RHEL 9 must define default permissions for the c shell.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-412065 - RHEL 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-431010 - RHEL 9 must use a Linux Security Module configured to enforce limits on system services.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

RHEL-09-431016 - RHEL 9 must elevate the SELinux context when an administrator calls the sudo command.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-431030 - RHEL 9 policycoreutils-python-utils package must be installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-433015 - RHEL 9 fapolicy module must be enabled.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611025 - RHEL 9 must not allow blank or null passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611035 - RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-611040 - RHEL 9 must ensure the password complexity module is enabled in the password-auth file.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611045 - RHEL 9 must ensure the password complexity module is enabled in the system-auth file.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611055 - RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611115 - RHEL 9 must require the change of at least eight characters when passwords are changed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611130 - RHEL 9 must require the change of at least four character classes when passwords are changed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611190 - RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611200 - RHEL 9 must require authentication to access single-user mode.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-651015 - RHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

RHEL-09-651025 - RHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-651035 - RHEL 9 must be configured so that the file integrity tool verifies extended attributes.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-652010 - RHEL 9 must have the rsyslog package installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652045 - RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY