Item Search

NameAudit NamePluginCategory
RHEL-08-040131 - RHEL 8 must mount /var/log/audit with the noexec option.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040135 - The RHEL 8 fapolicy module must be installed.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040136 - The RHEL 8 fapolicy module must be enabled.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040161 - RHEL 8 must force a frequent session key renegotiation for SSH connections to the server.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-08-040210 - RHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040221 - RHEL 8 must log IPv4 packets with impossible addresses.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-040270 - RHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040320 - The graphical display manager must not be installed on RHEL 8 unless approved.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040341 - The RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040400 - RHEL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-10-000510 - RHEL 10 must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information on local disk partitions that requires at-rest protection.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200000 - RHEL 10 must remove all software components after updated versions have been installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-200060 - RHEL 10 must not have the unbound package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200080 - RHEL 10 must not have the "gdm" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200520 - RHEL 10 must have the "s-nail" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200540 - RHEL 10 must have the "chrony" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200562 - RHEL 10 must block unauthorized peripherals before establishing a connection.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200563 - RHEL 10 must enable audit logging for the USBGuard daemon.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200600 - RHEL 10 must have the "fapolicy" module installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200621 - RHEL 10 must use the common access card (CAC) smart card driver.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200660 - RHEL 10 must have the "audit" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-200680 - RHEL 10 must have the "libreswan" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200730 - RHEL 10 must have the "pkcs11-provider" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-300030 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-300070 - RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400025 - RHEL 10 must be configured so that the "/etc/gshadow" file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400035 - RHEL 10 must be configured so that the "/etc/gshadow-" file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400045 - RHEL 10 must be configured so that the "/etc/passwd" file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400090 - RHEL 10 must be configured so that the "/var/log/"messages file is owned by root.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-400145 - RHEL 10 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400150 - RHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is group-owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400195 - RHEL 10 must enforce root ownership of the "/etc/audit/" directory.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-400240 - RHEL 10 must enforce mode "0750" or less permissive for local interactive user home directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400315 - RHEL 10 must define default permissions for the bash shell.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400330 - RHEL 10 must define default permissions for the system default profile.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400340 - RHEL 10 must enforce mode "0600" or less permissive for Secure Shell (SSH) private host key files.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400355 - RHEL 10 must prevent device files from being interpreted on file systems that contain user home directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-400410 - RHEL 10 must mount "/var/log/audit" with the "nosuid" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-500360 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "semanage" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500390 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500430 - RHEL 10 must generate audit records for successful and unsuccessful uses of the "chsh" command.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-500740 - RHEL 10 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/shadow".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-10-600100 - RHEL 10 must, for new users or password changes, have a 60-day maximum password lifetime restriction for user account passwords in "/etc/login.defs".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600120 - RHEL 10 must assign a home directory for local interactive user accounts upon creation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-600130 - RHEL 10 must not allow duplicate user IDs (UIDs) to exist for interactive users.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600210 - RHEL 10 must enforce a 24-hours minimum password lifetime restriction for passwords for new users or password changes in "/etc/login.defs".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600270 - RHEL 10 must enforce that passwords have a 24 hours/1 day minimum lifetime restriction in "/etc/shadow".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600280 - RHEL 10 must require the maximum number of repeating characters of the same character class to be limited to four when passwords are changed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600300 - RHEL 10 must require the change of at least four character classes when passwords are changed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600410 - RHEL 10 must automatically lock an account when three unsuccessful login attempts occur.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL