Item Search

NameAudit NamePluginCategory
2.1 Disable Local-only Graphical Login EnvironmentCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.3 Establish a Secure Baseline - Make sure that network/ftp:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/nfs/mapid:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/nfs/nlockmgr:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/nfs/status:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/cde-ttdbserver:tcp is only limited to local connectionsCIS Solaris 10 L1 v5.2Unix
2.5 Disable NIS Client Services - domainCIS Solaris 11.1 L1 v1.0.0Unix
2.6 Disable Kerberos TGT Expiration WarningCIS Solaris 11.1 L1 v1.0.0Unix
2.10 Disable Apache ServiceCIS Solaris 11.1 L1 v1.0.0Unix
2.11 Configure TCP Wrappers - hosts.allowCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Restrict Core Dumps to Protected Directory - /var/share/coresCIS Solaris 11.1 L1 v1.0.0Unix
3.1 Restrict Core Dumps to Protected Directory - global core dump logging = enabledCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - global core dumps = enabledCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

3.1.17 Set Maximum Number of Incoming Connections - Check tcp_conn_req_max_q value. Expected value: 1024.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.18 Lock down dtspcd(8) - Check tcp_extra_priv_ports_add value. Expected value: 6112.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2 Restrict Core Dumps to Protected Directory - Check if permissions for /var/cores are OK.CIS Solaris 10 L1 v5.2Unix
3.5 Disable Network Routing - Make sure that ipv4-forwarding is disabledCIS Solaris 10 L1 v5.2Unix
4.5 Enable Login Records - Check if loginlog in /etc/logadm.conf is appropiately setCIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.8 Enable System Accounting - Check if svc:/system/sar is onlineCIS Solaris 10 L1 v5.2Unix
5.2 Restrict Set-UID on User Mounted Devices - Check if nosuid option is set in /etc/rmmount.conf.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.1.3 Disable SSH X11 Forwarding - Check if X11Forwarding is set to no and not commented for the server.CIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

6.1.5 Set SSH MaxAuthTriesLog to 0 - Check if MaxAuthTriesLog is set to 0 and not commented for the server.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

6.1.6 Set SSH IgnoreRhosts to yes - Check if IgnoreRhosts is set to yes and not commented for the server.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.1.8 Set SSH RhostsRSAAuthentication to no - Check if RhostsRSAAuthentication is set to no and not commented for the server.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

6.1.10 Set SSH PermitEmptyPasswords to no - Check if PermitEmptyPasswords is set to no and not commented for the serverCIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

6.6 Set Delay between Failed Login Attempts to 4.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.7 Set Default Screen Lock for CDE Users - Check if 'dtsession*saverTimeout' is set to 10.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.8 Set Default Screen Lock for GNOME Users - Check if lockTimeout is set to 0:00:00 in /usr/openwin/lib/app-defaults/XScreenSaver.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.9 Restrict at/cron To Authorized Users - should pass if /etc/cron.d/at.deny does not exist.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.9 Restrict at/cron To Authorized Users - should pass if /etc/cron.d/cron.allow permissions are OK.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'bin' is locked.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'nobody' is locked.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'nuucp' is locked.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'sys' disallows password loginCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - Ensure account 'uucp' disallows password login.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'adm' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'bin' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'listen' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.1 Disable System Accounts - should pass if the default shell for 'nobody4' is set to /usr/bin/false.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.4 Set Default Group for root AccountCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.10 Ensure Password Encryption Uses SHA algorithms 'CRYPT_DEFAULT'CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

8.3 Create Warnings Banner for GNOME Users - Check if Greeter is set to /usr/bin/gdmloginCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.1 Check for Remote Consoles using 'consadm' command line utilityCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.3 Ensure Password Fields are Not Empty - Verify no accounts are returned by 'logins -p'CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

9.5 Verify that no UID 0 accounts exist other than rootCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

9.16 Check for Duplicate GIDsCIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

9.23 Find SUID/SGID System ExecutablesCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

10.2 Use full path names in /etc/dfs/dfstab fileCIS Solaris 10 L2 v5.2Unix

CONFIGURATION MANAGEMENT

10.5 Create symlinks for dangerous files - /.rhostsCIS Solaris 10 L2 v5.2Unix
10.6 Remove Support for Internet Services (inetd)CIS Solaris 10 L2 v5.2Unix