Item Search

NameAudit NamePluginCategory
RHEL-09-232103 - RHEL 9 "/etc/audit/" must be owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-232175 - RHEL 9 /var/log directory must be group-owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-09-232210 - RHEL 9 library directories must be owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-232235 - RHEL 9 cron configuration files directory must be group-owned by root.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-251030 - RHEL 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-251035 - RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-252010 - RHEL 9 must have the chrony package installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-252035 - RHEL 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-252065 - RHEL 9 libreswan package must be installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-253020 - RHEL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-253035 - RHEL 9 must use reverse path filtering on all IPv4 interfaces.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-253045 - RHEL 9 must not forward IPv4 source-routed packets by default.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-253070 - RHEL 9 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-254040 - RHEL 9 must not forward IPv6 source-routed packets by default.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-255015 - All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-255040 - RHEL 9 SSHD must not allow blank passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-255085 - RHEL 9 must not allow users to override SSH environment variables.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-255120 - RHEL 9 SSH private host key files must have mode 0600 or less permissive.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-255135 - RHEL 9 SSH daemon must not allow GSSAPI authentication.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-255145 - RHEL 9 SSH daemon must not allow rhosts authentication.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-255160 - RHEL 9 SSH daemon must perform strict mode checking of home directory configuration files.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-271025 - RHEL 9 must prevent a user from overriding the disabling of the graphical user interface automount function.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-271100 - RHEL 9 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-271110 - RHEL 9 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-271115 - RHEL 9 must disable the user list at logon for graphical user interfaces.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-291015 - RHEL 9 must have the USBGuard package installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-411010 - RHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-411050 - RHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-411080 - RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-412055 - RHEL 9 must define default permissions for the bash shell.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-412070 - RHEL 9 must define default permissions for the system default profile.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-432025 - RHEL 9 must require users to reauthenticate for privilege escalation.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-432030 - RHEL 9 must restrict privilege elevation to authorized personnel.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-433010 - RHEL 9 fapolicy module must be installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611050 - RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611070 - RHEL 9 must enforce password complexity by requiring that at least one numeric character be used.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611100 - RHEL 9 must enforce password complexity by requiring that at least one special character be used.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611105 - RHEL 9 must prevent the use of dictionary words for passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611145 - RHEL 9 must not be configured to bypass password requirements for privilege escalation.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-631010 - RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-631015 - RHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-651030 - RHEL 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-652015 - RHEL 9 must have the packages required for encrypting offloaded audit logs installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-652025 - RHEL 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-652040 - RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652050 - RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652055 - RHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-652060 - RHEL 9 must use cron logging.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-653060 - RHEL 9 must label all offloaded audit logs before sending them to the central log server.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

RHEL-09-653065 - RHEL 9 must take appropriate action when the internal event queue is full.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY