Item Search

NameAudit NamePluginCategory
RHEL-10-400215 - RHEL 10 must enforce mode "755" or less permissive for library files.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-400250 - RHEL 10 must enforce mode "0644" or less permissive for the "/etc/group-" file to prevent unauthorized access.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400255 - RHEL 10 must enforce mode "0000" or less permissive for the "/etc/gshadow" file to prevent unauthorized access.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400280 - RHEL 10 must be configured so that a sticky bit is set on all public directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-400335 - RHEL 10 must enforce that all local initialization files configured by systemd-tmpfiles have mode "0600" or less permissive.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400360 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that contain user home directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-500005 - RHEL 10 must enable auditing of processes that start prior to the audit daemon.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-500020 - RHEL 10 must log username information when unsuccessful login attempts occur.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-500030 - RHEL 10 must allocate an "audit_backlog_limit" of sufficient size to capture processes that start prior to the audit daemon.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500340 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfacl" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500370 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "setfiles" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500410 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "init_module" and "finit_module" system calls.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500490 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "passwd" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500530 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "ssh-keysign" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500560 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "sudoedit" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500570 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "unix_chkpwd" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500780 - RHEL 10 must generate audit records for all uses of the "chmod", "fchmod", "fchmodat", and "fchmodat2" syscalls.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500790 - RHEL 10 must generate audit records for all uses of the "chown", "fchown", "fchownat", and "lchown" syscalls.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500810 - RHEL 10 must generate audit records for all uses of the "rename", "unlink", "rmdir", "renameat", "renameat2", and "unlinkat" system calls.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-600010 - RHEL 10 must require a unique superusers name upon booting into single-user and maintenance modes.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600170 - RHEL 10 must be configured so that all local interactive user initialization file executable search path statements do not contain statements that will reference a working directory other than user home directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-600200 - RHEL 10 must enforce a delay of at least four seconds between login prompts following a failed login attempt.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600240 - RHEL 10 must enforce password complexity by requiring that at least one lowercase character be used.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600420 - RHEL 10 must automatically lock an account when three unsuccessful login attempts occur during a 15-minute time period.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600430 - RHEL 10 must ensure account lockouts persist.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600510 - RHEL 10 must be configured to not bypass password requirements for privilege escalation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600540 - RHEL 10 must require reauthentication when using the "sudo" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600550 - RHEL 10 must use the invoking user's password for privilege escalation when using "sudo".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600610 - RHEL 10 must configure the use of the pam_faillock.so module in the "/etc/pam.d/password-auth" file.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-600720 - RHEL 10 must be configured so that password-auth uses a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700020 - RHEL 10 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user login.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700110 - RHEL 10 must prevent files with the "setuid" and "setgid" bit set from being executed on file systems that are imported via Network File System (NFS).DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700150 - RHEL 10 must mount "/tmp" with the "nodev" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700180 - RHEL 10 must mount "/var/log" with the "nosuid" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700190 - RHEL 10 must mount "/var/tmp" with the "noexec" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700570 - RHEL 10 must be configured so that the Secure Shell (SSH) daemon displays the date and time of the last successful account login upon an SSH login.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-700610 - RHEL 10 must be configured so that SSHD does not allow blank passwords.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700620 - RHEL 10 must not permit direct logins to the root account using remote access via Secure Shell (SSH).DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700630 - RHEL 10 must not allow a noncertificate trusted host Secure Shell (SSH) login to the system.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700650 - RHEL 10 must force a frequent session key renegotiation for Secure Shell (SSH) connections to the server.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-700690 - RHEL 10 must not have any ".shosts" files on the system.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700710 - RHEL 10 must prevent a user from overriding the disabling of the graphical user interface autorun function.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700760 - RHEL 10 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700900 - RHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-701000 - RHEL 10 must clear the page allocator to prevent use-after-free attacks.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701030 - RHEL 10 must restrict access to the kernel message buffer.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701040 - RHEL 10 must prevent kernel profiling by nonprivileged users.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701050 - RHEL 10 must prevent the loading of a new kernel for later execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-701140 - RHEL 10 must restrict usage of ptrace to descendant processes.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-701200 - RHEL 10 must disable the kdump service.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION