Item Search

NameAudit NamePluginCategory
GEN003601 - TCP backlog queue sizes must be set appropriately - dladm show-linkDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003603 - The system must not respond to ICMPv4 echoes sent to a broadcast address - dladm show-linkDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003603 - The system must not respond to ICMPv4 echoes sent to a broadcast address.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003623 - The system must use a separate file system for the system audit data path - df -h AUDIT_DIRDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003624 - The system must use a separate filesystem for /tmp (or equivalent).DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003720 - The inetd.conf file must be owned by root or bin.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN003730 - The inetd.conf file must be group-owned by root, bin, or sys.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003780 - The services file must have mode 0444 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN003820 - The rsh daemon must not be running.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN003845 - The rexecd service must not be installed.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN004360 - The alias file must be owned by root.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004380 - The alias file must have mode 0644 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004400 - Files executed through a mail aliases file must be owned by root and must reside within a directory owned and writable only by root.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004440 - Sendmail logging must not be set to less than nine in the sendmail.cf file.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN004480 - The SMTP service log file must be owned by root - /var/log/syslogDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004500 - The SMTP service log file must have mode 0644 or less permissive - /var/adm/messagesDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004500 - The SMTP service log file must have mode 0644 or less permissive - /var/log/syslogDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004510 - The SMTP service log file must not have an extended ACL.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005120 - The TFTP daemon must be configured to vendor specifications, including a dedicated TFTP user account, a non-login shell, such as /bin/false, and a home directory owned by the TFTP user - dedicated TFTP accountDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005120 - The TFTP daemon must be configured to vendor specifications, including a dedicated TFTP user account, a non-login shell, such as /bin/false, and a home directory owned by the TFTP user - home directoryDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005120 - The TFTP daemon must be configured to vendor specifications, including a dedicated TFTP user account, a non-login shell, such as /bin/false, and a home directory owned by the TFTP user.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005140 - Any active TFTP daemon must be authorized and approved in the system accreditation package.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005202 - The sshd server must bind the X11 forwarding server to the loopback address.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005240 - The .Xauthority utility must only permit access to authorized hosts.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /var/sma_snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005305 - The SNMP service must use only SNMPv3 or its successors - /etc/sma/snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005305 - The SNMP service must use only SNMPv3 or its successors - /var/sma_snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005350 - Management Information Base (MIB) files must not have extended ACLs.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005360 - The snmpd.conf files must be owned by root - /etc/snmp/conf/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005365 - The snmpd.conf file must be group-owned by root, sys, or bin - /usr/sfw/lib/sma_snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005395 - The /etc/syslog.conf file must not have an extended ACL.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005501 - The SSH client must be configured to only use the SSHv2 protocol.DISA STIG Solaris 10 X86 v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN005540 - The SSH daemon must be configured for IP filtering.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005570 - The system must be configured with a default gateway for IPv6 if the system uses IPv6, unless the system is a router.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005820 - The NFS anonymous UID and GID must be configured to values that have no permissions.DISA STIG Solaris 10 X86 v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN006060 - The system must not run Samba unless needed.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006080 - The Samba Web Administration Tool (SWAT) must be restricted to the local host or require SSL - hosts.denyDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006080 - The Samba Web Administration Tool (SWAT) must be restricted to the local host or require SSL - ServiceDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006150 - The smb.conf file must not have an extended ACL.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006360 - The files in /etc/news must be group-owned by root - /etc/news/*DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006400 - The Network Information System (NIS) protocol must not be used.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006571 - The file integrity tool must be configured to verify extended attributes - usedDISA STIG Solaris 10 X86 v2r4Unix

SYSTEM AND INFORMATION INTEGRITY

GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents - usedDISA STIG Solaris 10 X86 v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN007540 - The Transparent Inter-Process Communication (TIPC) protocol must be disabled or not installed.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007820 - The system must not have IP tunnels configured.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007860 - The system must ignore IPv6 ICMP redirect messages - dladm show-linkDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007920 - The system must not forward IPv6 source-routed packets - dladm show-linkDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007980 - If the system is using LDAP for authentication or account information, the system must use a TLS connection using FIPS 140-2 approved cryptographic algorithms - configuredDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN008120 - If the system is using LDAP for authentication or account information, the /etc/ldap.conf (or equivalent) file must not have an extended ACL - ldap_client_credDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN008140 - If the system is using LDAP for authentication or account information, the TLS certificate authority file and/or directory (as appropriate) must be owned by root - secmod.dbDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT