93.6 MB
/srv/reproducible-results/rbuild-debian/r-b-build.dMrVcbxe/b1/scap-security-guide_0.1.76-1_arm64.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.dMrVcbxe/b2/scap-security-guide_0.1.76-1_arm64.changes
824 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·3b961349f689d4e76153f715f366baba·153748·admin·optional·ssg-applications_0.1.76-1_all.deb1 ·73b99687142a6b4bc2cb738ea816afc5·153744·admin·optional·ssg-applications_0.1.76-1_all.deb
2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb
3 ·e8d8b5d07fc10b7a7ca1d90b2545e4ce·3725952·admin·optional·ssg-debderived_0.1.76-1_all.deb 
4 ·6d3e00a0583a40561c16ee4c551363c6·1232524·admin·optional·ssg-debian_0.1.76-1_all.deb 
5 ·af0ef7e3bdcf4e0bc0b4c5dbdc65fc0d·37102652·admin·optional·ssg-nondebian_0.1.76-1_all.deb3 ·d5ad0488f0c9ac7ed76db154519c44fa·3725856·admin·optional·ssg-debderived_0.1.76-1_all.deb
 4 ·d85ff4175cbf8e8a59386b5d3100e52c·1232372·admin·optional·ssg-debian_0.1.76-1_all.deb
 5 ·d9e2b953a3fda287fec0899bdc9642fe·37099656·admin·optional·ssg-nondebian_0.1.76-1_all.deb
407 KB
ssg-applications_0.1.76-1_all.deb
370 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1724·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1720·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0···151832·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0···151832·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
406 KB
data.tar.xz
406 KB
data.tar
77.1 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
77.0 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">
29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Chromium.·It·is·a·rendering·of40 configuration·settings·for·Chromium.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1675, 15 lines modifiedOffset 1675, 15 lines modified
1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">
1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>
1677 ··········</xccdf-1.2:check>1677 ··········</xccdf-1.2:check>
1678 ········</xccdf-1.2:Rule>1678 ········</xccdf-1.2:Rule>
1679 ······</xccdf-1.2:Group>1679 ······</xccdf-1.2:Group>
1680 ····</xccdf-1.2:Benchmark>1680 ····</xccdf-1.2:Benchmark>
1681 ··</ds:component>1681 ··</ds:component>
1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-02-28T20:08:00">1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-03-01T22:08:00">
1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1684 ······<oval-def:generator>1684 ······<oval-def:generator>
1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
1687 ········<oval:schema_version>5.11</oval:schema_version>1687 ········<oval:schema_version>5.11</oval:schema_version>
1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1689 ······</oval-def:generator>1689 ······</oval-def:generator>
Offset 2539, 400 lines modifiedOffset 2539, 400 lines modified
2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>
2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>
2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>
2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>
2543 ······</oval-def:variables>2543 ······</oval-def:variables>
2544 ····</oval-def:oval_definitions>2544 ····</oval-def:oval_definitions>
2545 ··</ds:component>2545 ··</ds:component>
2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-02-28T20:08:00">2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-03-01T22:08:00">
2547 ····<ocil:ocil>2547 ····<ocil:ocil>
2548 ······<ocil:generator>2548 ······<ocil:generator>
2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2551 ········<ocil:schema_version>2.0</ocil:schema_version>2551 ········<ocil:schema_version>2.0</ocil:schema_version>
2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2553 ······</ocil:generator>2553 ······</ocil:generator>
2554 ······<ocil:questionnaires>2554 ······<ocil:questionnaires>
2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1"> 
2556 ··········<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title> 
2557 ··········<ocil:actions> 
2558 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref> 
2559 ··········</ocil:actions> 
2560 ········</ocil:questionnaire> 
2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1"> 
2562 ··········<ocil:title>Disable·All·Extensions·by·Default</ocil:title> 
2563 ··········<ocil:actions> 
2564 ············<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref> 
2565 ··········</ocil:actions> 
2566 ········</ocil:questionnaire> 
2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1"> 
2568 ··········<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title> 
2569 ··········<ocil:actions> 
2570 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref> 
2571 ··········</ocil:actions> 
2572 ········</ocil:questionnaire> 
2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
2574 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title>2556 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
2575 ··········<ocil:actions>2557 ··········<ocil:actions>
2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>2558 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
2577 ··········</ocil:actions>2559 ··········</ocil:actions>
2578 ········</ocil:questionnaire>2560 ········</ocil:questionnaire>
2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
2580 ··········<ocil:title>Prevent·Desktop·Notifications</ocil:title>2562 ··········<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
2581 ··········<ocil:actions>2563 ··········<ocil:actions>
2582 ············<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>2564 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
2583 ··········</ocil:actions>2565 ··········</ocil:actions>
2584 ········</ocil:questionnaire>2566 ········</ocil:questionnaire>
2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
2586 ··········<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>2568 ··········<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
2587 ··········<ocil:actions>2569 ··········<ocil:actions>
2588 ············<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>2570 ············<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
2589 ··········</ocil:actions>2571 ··········</ocil:actions>
2590 ········</ocil:questionnaire>2572 ········</ocil:questionnaire>
2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">
2592 ··········<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>2574 ··········<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>
2593 ··········<ocil:actions>2575 ··········<ocil:actions>
2594 ············<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>
2595 ··········</ocil:actions>2577 ··········</ocil:actions>
2596 ········</ocil:questionnaire>2578 ········</ocil:questionnaire>
2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
2598 ··········<ocil:title>Block·Plugins·by·Default</ocil:title>2580 ··········<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
2599 ··········<ocil:actions>2581 ··········<ocil:actions>
 2582 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
 2583 ··········</ocil:actions>
 2584 ········</ocil:questionnaire>
 2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
 2586 ··········<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
 2587 ··········<ocil:actions>
2600 ············<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>2588 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
2601 ··········</ocil:actions>2589 ··········</ocil:actions>
2602 ········</ocil:questionnaire>2590 ········</ocil:questionnaire>
2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">
2604 ··········<ocil:title>Disable·Network·Prediction</ocil:title>2592 ··········<ocil:title>Disable·Network·Prediction</ocil:title>
2605 ··········<ocil:actions>2593 ··········<ocil:actions>
2606 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>2594 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>
2607 ··········</ocil:actions>2595 ··········</ocil:actions>
2608 ········</ocil:questionnaire>2596 ········</ocil:questionnaire>
2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
2610 ··········<ocil:title>Set·the·Default·Home·Page</ocil:title>2598 ··········<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
2611 ··········<ocil:actions>2599 ··········<ocil:actions>
2612 ············<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>2600 ············<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
2613 ··········</ocil:actions>2601 ··········</ocil:actions>
2614 ········</ocil:questionnaire>2602 ········</ocil:questionnaire>
2615 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
2616 ··········<ocil:title>Disable·Saved·Passwords</ocil:title>2604 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
2617 ··········<ocil:actions>2605 ··········<ocil:actions>
2618 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>2606 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
2619 ··········</ocil:actions>2607 ··········</ocil:actions>
Max diff block lines reached; 68108/78779 bytes (86.45%) of diff not shown.
68.6 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
68.5 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
Ordering differences only
    
Offset 3, 391 lines modifiedOffset 3, 391 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1"> 
23 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
29 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title>11 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
35 ······<ocil:title>Prevent·Desktop·Notifications</ocil:title>17 ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
41 ······<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>23 ······<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">
47 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>29 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
53 ······<ocil:title>Block·Plugins·by·Default</ocil:title>35 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
 37 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
 38 ······</ocil:actions>
 39 ····</ocil:questionnaire>
 40 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
 41 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
 42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Network·Prediction</ocil:title>47 ······<ocil:title>Disable·Network·Prediction</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
65 ······<ocil:title>Set·the·Default·Home·Page</ocil:title>53 ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Saved·Passwords</ocil:title>59 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Background·Processing</ocil:title>65 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">
83 ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title>71 ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">
89 ······<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>77 ······<ocil:title>Set·the·Default·Home·Page</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">
95 ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title>83 ······<ocil:title>Prevent·Desktop·Notifications</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>89 ······<ocil:title>Block·Plugins·by·Default</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
 91 ········<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>
 92 ······</ocil:actions>
 93 ····</ocil:questionnaire>
 94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·Background·Processing</ocil:title>
 96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>101 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>107 ······<ocil:title>Disable·Outdated·Plugins</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
Max diff block lines reached; 59291/69990 bytes (84.71%) of diff not shown.
85.1 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
85.0 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">
33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">
37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1545, 15 lines modifiedOffset 1545, 15 lines modified
1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>
1546 ············</xccdf-1.2:check>1546 ············</xccdf-1.2:check>
1547 ··········</xccdf-1.2:Rule>1547 ··········</xccdf-1.2:Rule>
1548 ········</xccdf-1.2:Group>1548 ········</xccdf-1.2:Group>
1549 ······</xccdf-1.2:Group>1549 ······</xccdf-1.2:Group>
1550 ····</xccdf-1.2:Benchmark>1550 ····</xccdf-1.2:Benchmark>
1551 ··</ds:component>1551 ··</ds:component>
1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-02-28T20:08:00">1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-03-01T22:08:00">
1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1554 ······<oval-def:generator>1554 ······<oval-def:generator>
1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
1557 ········<oval:schema_version>5.11</oval:schema_version>1557 ········<oval:schema_version>5.11</oval:schema_version>
1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1559 ······</oval-def:generator>1559 ······</oval-def:generator>
Offset 2166, 506 lines modifiedOffset 2166, 620 lines modified
2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>
2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">
2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>
2169 ········</oval-def:local_variable>2169 ········</oval-def:local_variable>
2170 ······</oval-def:variables>2170 ······</oval-def:variables>
2171 ····</oval-def:oval_definitions>2171 ····</oval-def:oval_definitions>
2172 ··</ds:component>2172 ··</ds:component>
2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-02-28T20:08:00">2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-03-01T22:08:00">
2174 ····<ocil:ocil>2174 ····<ocil:ocil>
2175 ······<ocil:generator>2175 ······<ocil:generator>
2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2178 ········<ocil:schema_version>2.0</ocil:schema_version>2178 ········<ocil:schema_version>2.0</ocil:schema_version>
2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2180 ······</ocil:generator>2180 ······</ocil:generator>
2181 ······<ocil:questionnaires>2181 ······<ocil:questionnaires>
2182 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">2182 ········<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">
2183 ··········<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>2183 ··········<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>
2184 ··········<ocil:actions>2184 ··········<ocil:actions>
2185 ············<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>2185 ············<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>
2186 ··········</ocil:actions>2186 ··········</ocil:actions>
2187 ········</ocil:questionnaire>2187 ········</ocil:questionnaire>
2188 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">2188 ········<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">
2189 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>2189 ··········<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>
2190 ··········<ocil:actions>2190 ··········<ocil:actions>
2191 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>2191 ············<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>
2192 ··········</ocil:actions>2192 ··········</ocil:actions>
2193 ········</ocil:questionnaire>2193 ········</ocil:questionnaire>
2194 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">2194 ········<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">
2195 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>2195 ··········<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>
2196 ··········<ocil:actions>2196 ··········<ocil:actions>
2197 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>2197 ············<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>
2198 ··········</ocil:actions>2198 ··········</ocil:actions>
2199 ········</ocil:questionnaire>2199 ········</ocil:questionnaire>
2200 ········<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">2200 ········<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">
2201 ··········<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>2201 ··········<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>
2202 ··········<ocil:actions>2202 ··········<ocil:actions>
2203 ············<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>2203 ············<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>
2204 ··········</ocil:actions>2204 ··········</ocil:actions>
2205 ········</ocil:questionnaire>2205 ········</ocil:questionnaire>
2206 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> 
2207 ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>2206 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
 2207 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
2208 ··········<ocil:actions>2208 ··········<ocil:actions>
2209 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>2209 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
2210 ··········</ocil:actions>2210 ··········</ocil:actions>
2211 ········</ocil:questionnaire>2211 ········</ocil:questionnaire>
2212 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">2212 ········<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
2213 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>2213 ··········<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
2214 ··········<ocil:actions>2214 ··········<ocil:actions>
2215 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>2215 ············<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
2216 ··········</ocil:actions>2216 ··········</ocil:actions>
2217 ········</ocil:questionnaire>2217 ········</ocil:questionnaire>
2218 ········<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">2218 ········<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
2219 ··········<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>2219 ··········<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
2220 ··········<ocil:actions>2220 ··········<ocil:actions>
2221 ············<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>2221 ············<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
2222 ··········</ocil:actions>2222 ··········</ocil:actions>
2223 ········</ocil:questionnaire>2223 ········</ocil:questionnaire>
2224 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">2224 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">
2225 ··········<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>2225 ··········<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>
2226 ··········<ocil:actions>2226 ··········<ocil:actions>
 2227 ············<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>
 2228 ··········</ocil:actions>
 2229 ········</ocil:questionnaire>
 2230 ········<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1">
 2231 ··········<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>
 2232 ··········<ocil:actions>
 2233 ············<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>
 2234 ··········</ocil:actions>
 2235 ········</ocil:questionnaire>
 2236 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">
 2237 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
 2238 ··········<ocil:actions>
 2239 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>
 2240 ··········</ocil:actions>
 2241 ········</ocil:questionnaire>
 2242 ········<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">
 2243 ··········<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>
Max diff block lines reached; 75089/86916 bytes (86.39%) of diff not shown.
76.5 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
76.4 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
Ordering differences only
    
Offset 3, 497 lines modifiedOffset 3, 611 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">
11 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>11 ······<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">
17 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>17 ······<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>23 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>29 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> 
35 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
 35 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
41 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>41 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
47 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>47 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>53 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
 55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_conf_action:testaction:1</ocil:test_action_ref>
 56 ······</ocil:actions>
 57 ····</ocil:questionnaire>
 58 ····<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1">
 59 ······<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>
 60 ······<ocil:actions>
 61 ········<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>
 62 ······</ocil:actions>
 63 ····</ocil:questionnaire>
 64 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">
 65 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
 66 ······<ocil:actions>
 67 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>
 68 ······</ocil:actions>
 69 ····</ocil:questionnaire>
 70 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>
 72 ······<ocil:actions>
 73 ········<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>
 74 ······</ocil:actions>
 75 ····</ocil:questionnaire>
 76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">
 77 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
 78 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>80 ······</ocil:actions>
57 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
59 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>83 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
60 ······<ocil:actions>84 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>86 ······</ocil:actions>
63 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1"> 
65 ······<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1">
 89 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
66 ······<ocil:actions>90 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>92 ······</ocil:actions>
69 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>95 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
72 ······<ocil:actions>96 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>98 ······</ocil:actions>
75 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>101 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
78 ······<ocil:actions>102 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>104 ······</ocil:actions>
81 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">
83 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>107 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
84 ······<ocil:actions>108 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>110 ······</ocil:actions>
87 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">
89 ······<ocil:title>Only·use·approved·container·registries</ocil:title>113 ······<ocil:title>Only·use·approved·container·registries</ocil:title>
90 ······<ocil:actions>114 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>116 ······</ocil:actions>
93 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
96 ······<ocil:actions> 
97 ········<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref> 
98 ······</ocil:actions> 
99 ····</ocil:questionnaire> 
100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>119 ······<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>
102 ······<ocil:actions>120 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 67774/78085 bytes (86.80%) of diff not shown.
52.9 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
52.8 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">
29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Firefox.·It·is·a·rendering·of40 configuration·settings·for·Firefox.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 3488, 15 lines modifiedOffset 3488, 15 lines modified
3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>
3489 ············</xccdf-1.2:check>3489 ············</xccdf-1.2:check>
3490 ··········</xccdf-1.2:Rule>3490 ··········</xccdf-1.2:Rule>
3491 ········</xccdf-1.2:Group>3491 ········</xccdf-1.2:Group>
3492 ······</xccdf-1.2:Group>3492 ······</xccdf-1.2:Group>
3493 ····</xccdf-1.2:Benchmark>3493 ····</xccdf-1.2:Benchmark>
3494 ··</ds:component>3494 ··</ds:component>
3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-02-28T20:08:00">3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-03-01T22:08:00">
3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
3497 ······<oval-def:generator>3497 ······<oval-def:generator>
3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
3500 ········<oval:schema_version>5.11</oval:schema_version>3500 ········<oval:schema_version>5.11</oval:schema_version>
3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
3502 ······</oval-def:generator>3502 ······</oval-def:generator>
Offset 5198, 200 lines modifiedOffset 5198, 200 lines modified
5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>
5199 ············</oval-def:concat>5199 ············</oval-def:concat>
5200 ··········</oval-def:unique>5200 ··········</oval-def:unique>
5201 ········</oval-def:local_variable>5201 ········</oval-def:local_variable>
5202 ······</oval-def:variables>5202 ······</oval-def:variables>
5203 ····</oval-def:oval_definitions>5203 ····</oval-def:oval_definitions>
5204 ··</ds:component>5204 ··</ds:component>
5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-02-28T20:08:00">5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-03-01T22:08:00">
5206 ····<ocil:ocil>5206 ····<ocil:ocil>
5207 ······<ocil:generator>5207 ······<ocil:generator>
5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
5210 ········<ocil:schema_version>2.0</ocil:schema_version>5210 ········<ocil:schema_version>2.0</ocil:schema_version>
5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
5212 ······</ocil:generator>5212 ······</ocil:generator>
5213 ······<ocil:questionnaires>5213 ······<ocil:questionnaires>
5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
5215 ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>5215 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
5216 ··········<ocil:actions>5216 ··········<ocil:actions>
5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
5218 ··········</ocil:actions>5218 ··········</ocil:actions>
5219 ········</ocil:questionnaire>5219 ········</ocil:questionnaire>
5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
5221 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title>5221 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
5222 ··········<ocil:actions>5222 ··········<ocil:actions>
5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
5224 ··········</ocil:actions>5224 ··········</ocil:actions>
5225 ········</ocil:questionnaire>5225 ········</ocil:questionnaire>
5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
5227 ··········<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>5227 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
5228 ··········<ocil:actions>5228 ··········<ocil:actions>
5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
5230 ··········</ocil:actions>5230 ··········</ocil:actions>
5231 ········</ocil:questionnaire>5231 ········</ocil:questionnaire>
5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
5233 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>5233 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title>
5234 ··········<ocil:actions>5234 ··········<ocil:actions>
5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
5236 ··········</ocil:actions>5236 ··········</ocil:actions>
5237 ········</ocil:questionnaire>5237 ········</ocil:questionnaire>
5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
5239 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>5239 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
5240 ··········<ocil:actions>5240 ··········<ocil:actions>
5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
5242 ··········</ocil:actions>5242 ··········</ocil:actions>
5243 ········</ocil:questionnaire>5243 ········</ocil:questionnaire>
5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
5245 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>5245 ··········<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>
5246 ··········<ocil:actions>5246 ··········<ocil:actions>
5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
5248 ··········</ocil:actions>5248 ··········</ocil:actions>
5249 ········</ocil:questionnaire>5249 ········</ocil:questionnaire>
5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
5251 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title>5251 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
5252 ··········<ocil:actions>5252 ··········<ocil:actions>
5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
5254 ··········</ocil:actions>5254 ··········</ocil:actions>
5255 ········</ocil:questionnaire>5255 ········</ocil:questionnaire>
5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">
5257 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>5257 ··········<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>
5258 ··········<ocil:actions>5258 ··········<ocil:actions>
5259 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>
5260 ··········</ocil:actions>5260 ··········</ocil:actions>
5261 ········</ocil:questionnaire>5261 ········</ocil:questionnaire>
5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
5263 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>5263 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>
5264 ··········<ocil:actions>5264 ··········<ocil:actions>
5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
5266 ··········</ocil:actions>5266 ··········</ocil:actions>
5267 ········</ocil:questionnaire>5267 ········</ocil:questionnaire>
5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
5269 ··········<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>5269 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
5270 ··········<ocil:actions>5270 ··········<ocil:actions>
5271 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>5271 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
5272 ··········</ocil:actions>5272 ··········</ocil:actions>
5273 ········</ocil:questionnaire>5273 ········</ocil:questionnaire>
5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
5275 ··········<ocil:title>Enable·Shared·System·Certificates</ocil:title>5275 ··········<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
5276 ··········<ocil:actions>5276 ··········<ocil:actions>
5277 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>5277 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
5278 ··········</ocil:actions>5278 ··········</ocil:actions>
5279 ········</ocil:questionnaire>5279 ········</ocil:questionnaire>
5280 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">5280 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
5281 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>5281 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
5282 ··········<ocil:actions>5282 ··········<ocil:actions>
5283 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>5283 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
5284 ··········</ocil:actions>5284 ··········</ocil:actions>
Max diff block lines reached; 42098/53978 bytes (77.99%) of diff not shown.
45.9 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
45.8 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
Ordering differences only
    
Offset 3, 191 lines modifiedOffset 3, 191 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
11 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>11 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>17 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
23 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>23 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>29 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
35 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>35 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
41 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>41 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>47 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">
53 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>53 ······<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
59 ······<ocil:title>Enable·Certificate·Verification</ocil:title>59 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>65 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
71 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>71 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
77 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>77 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">
83 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>83 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
89 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>89 ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>95 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
101 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>101 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
 103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
 104 ······</ocil:actions>
 105 ····</ocil:questionnaire>
 106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>
 108 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>110 ······</ocil:actions>
105 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
107 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>113 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
108 ······<ocil:actions>114 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>116 ······</ocil:actions>
111 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
113 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>119 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>
114 ······<ocil:actions>120 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>122 ······</ocil:actions>
117 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">
119 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>125 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>
120 ······<ocil:actions>126 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>127 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>128 ······</ocil:actions>
123 ····</ocil:questionnaire>129 ····</ocil:questionnaire>
Max diff block lines reached; 34293/46784 bytes (73.30%) of diff not shown.
9.96 MB
ssg-debderived_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··3722716·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··3722620·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
9.96 MB
data.tar.xz
9.96 MB
data.tar
696 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
696 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1604-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1604-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.xenial.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.xenial.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·16.04·(Xenial)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1604:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 63230, 15 lines modifiedOffset 63230, 15 lines modified
63230 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>63230 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1604-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
63231 ············</xccdf-1.2:check>63231 ············</xccdf-1.2:check>
63232 ··········</xccdf-1.2:Rule>63232 ··········</xccdf-1.2:Rule>
63233 ········</xccdf-1.2:Group>63233 ········</xccdf-1.2:Group>
63234 ······</xccdf-1.2:Group>63234 ······</xccdf-1.2:Group>
63235 ····</xccdf-1.2:Benchmark>63235 ····</xccdf-1.2:Benchmark>
63236 ··</ds:component>63236 ··</ds:component>
63237 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-02-28T20:08:00">63237 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-oval.xml"·timestamp="2025-03-01T22:08:00">
63238 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">63238 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
63239 ······<oval-def:generator>63239 ······<oval-def:generator>
63240 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>63240 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
63241 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>63241 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
63242 ········<oval:schema_version>5.11</oval:schema_version>63242 ········<oval:schema_version>5.11</oval:schema_version>
63243 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>63243 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
63244 ······</oval-def:generator>63244 ······</oval-def:generator>
Offset 79818, 4882 lines modifiedOffset 79818, 4981 lines modified
79818 ············</oval-def:arithmetic>79818 ············</oval-def:arithmetic>
79819 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>79819 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
79820 ··········</oval-def:arithmetic>79820 ··········</oval-def:arithmetic>
79821 ········</oval-def:local_variable>79821 ········</oval-def:local_variable>
79822 ······</oval-def:variables>79822 ······</oval-def:variables>
79823 ····</oval-def:oval_definitions>79823 ····</oval-def:oval_definitions>
79824 ··</ds:component>79824 ··</ds:component>
79825 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-02-28T20:08:00">79825 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1604-ocil.xml"·timestamp="2025-03-01T22:08:00">
79826 ····<ocil:ocil>79826 ····<ocil:ocil>
79827 ······<ocil:generator>79827 ······<ocil:generator>
79828 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>79828 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
79829 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>79829 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
79830 ········<ocil:schema_version>2.0</ocil:schema_version>79830 ········<ocil:schema_version>2.0</ocil:schema_version>
79831 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>79831 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
79832 ······</ocil:generator>79832 ······</ocil:generator>
79833 ······<ocil:questionnaires>79833 ······<ocil:questionnaires>
79834 ········<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">79834 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
79835 ··········<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>79835 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
79836 ··········<ocil:actions>79836 ··········<ocil:actions>
79837 ············<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>79837 ············<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
79838 ··········</ocil:actions>79838 ··········</ocil:actions>
79839 ········</ocil:questionnaire>79839 ········</ocil:questionnaire>
79840 ········<ocil:questionnaire·id="ocil:ssg-service_timesyncd_enabled_ocil:questionnaire:1">79840 ········<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
79841 ··········<ocil:title>Enable·systemd_timesyncd·Service</ocil:title>79841 ··········<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>
79842 ··········<ocil:actions>79842 ··········<ocil:actions>
79843 ············<ocil:test_action_ref>ocil:ssg-service_timesyncd_enabled_action:testaction:1</ocil:test_action_ref>79843 ············<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
79844 ··········</ocil:actions>79844 ··········</ocil:actions>
79845 ········</ocil:questionnaire>79845 ········</ocil:questionnaire>
79846 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">79846 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
79847 ··········<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>79847 ··········<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>
79848 ··········<ocil:actions>79848 ··········<ocil:actions>
79849 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>79849 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
79850 ··········</ocil:actions>79850 ··········</ocil:actions>
79851 ········</ocil:questionnaire>79851 ········</ocil:questionnaire>
79852 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">79852 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
79853 ··········<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>79853 ··········<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
79854 ··········<ocil:actions>79854 ··········<ocil:actions>
79855 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>79855 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
79856 ··········</ocil:actions>79856 ··········</ocil:actions>
79857 ········</ocil:questionnaire>79857 ········</ocil:questionnaire>
79858 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">79858 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">
79859 ··········<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>79859 ··········<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>
79860 ··········<ocil:actions>79860 ··········<ocil:actions>
79861 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>79861 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
79862 ··········</ocil:actions>79862 ··········</ocil:actions>
79863 ········</ocil:questionnaire>79863 ········</ocil:questionnaire>
79864 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1"> 
79865 ··········<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>79864 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1">
 79865 ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title>
79866 ··········<ocil:actions>79866 ··········<ocil:actions>
79867 ············<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>79867 ············<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>
79868 ··········</ocil:actions>79868 ··········</ocil:actions>
79869 ········</ocil:questionnaire>79869 ········</ocil:questionnaire>
79870 ········<ocil:questionnaire·id="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1">79870 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
79871 ··········<ocil:title>Configure·the·confidence·in·TPM·for·entropy</ocil:title>79871 ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title>
79872 ··········<ocil:actions>79872 ··········<ocil:actions>
79873 ············<ocil:test_action_ref>ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1</ocil:test_action_ref>79873 ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
79874 ··········</ocil:actions>79874 ··········</ocil:actions>
79875 ········</ocil:questionnaire>79875 ········</ocil:questionnaire>
79876 ········<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">79876 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1">
79877 ··········<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>79877 ··········<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>
79878 ··········<ocil:actions>79878 ··········<ocil:actions>
79879 ············<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>79879 ············<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>
79880 ··········</ocil:actions>79880 ··········</ocil:actions>
79881 ········</ocil:questionnaire>79881 ········</ocil:questionnaire>
79882 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">79882 ········<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">
79883 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>79883 ··········<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>
79884 ··········<ocil:actions>79884 ··········<ocil:actions>
79885 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>79885 ············<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>
79886 ··········</ocil:actions>79886 ··········</ocil:actions>
79887 ········</ocil:questionnaire>79887 ········</ocil:questionnaire>
79888 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">79888 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">
79889 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>79889 ··········<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>
79890 ··········<ocil:actions>79890 ··········<ocil:actions>
79891 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>79891 ············<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>
79892 ··········</ocil:actions>79892 ··········</ocil:actions>
79893 ········</ocil:questionnaire>79893 ········</ocil:questionnaire>
79894 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">79894 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">
79895 ··········<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>79895 ··········<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>
79896 ··········<ocil:actions>79896 ··········<ocil:actions>
79897 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>79897 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
79898 ··········</ocil:actions>79898 ··········</ocil:actions>
79899 ········</ocil:questionnaire>79899 ········</ocil:questionnaire>
79900 ········<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">79900 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
79901 ··········<ocil:title>Ensure·Software·Patches·Installed</ocil:title>79901 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
79902 ··········<ocil:actions>79902 ··········<ocil:actions>
79903 ············<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>79903 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 700089/712673 bytes (98.23%) of diff not shown.
662 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
662 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
Ordering differences only
    
Offset 3, 4873 lines modifiedOffset 3, 4972 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
11 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>11 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-service_timesyncd_enabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
17 ······<ocil:title>Enable·systemd_timesyncd·Service</ocil:title>17 ······<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-service_timesyncd_enabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
23 ······<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>23 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
29 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>29 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
47 ······<ocil:title>Configure·the·confidence·in·TPM·for·entropy</ocil:title>47 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">
59 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>59 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">
65 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>65 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">
71 ······<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>71 ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·Software·Patches·Installed</ocil:title>77 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">
83 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>83 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_binary_dirs_ocil:questionnaire:1"> 
89 ······<ocil:title>Verify·that·System·Executables·Have·Restrictive·Permissions</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">
 89 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
95 ······<ocil:title>Disable·X11·Forwarding</ocil:title>95 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>101 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·the·32-bit·vDSO</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
113 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>113 ······<ocil:title>Install·the·ntp·service</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
119 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>119 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
125 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>125 ······<ocil:title>Kernel·panic·timeout</ocil:title>
Max diff block lines reached; 665018/677786 bytes (98.12%) of diff not shown.
731 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
731 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu1804-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu1804-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-com.ubuntu.bionic.usn.oval.xml.bz2"·xlink:href="https://security-metadata.canonical.com/oval/com.ubuntu.bionic.usn.oval.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">30 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~">
31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·18.04·(Bionic·Beaver)</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu1804:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of42 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 67111, 15 lines modifiedOffset 67111, 15 lines modified
67111 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>67111 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu1804-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
67112 ············</xccdf-1.2:check>67112 ············</xccdf-1.2:check>
67113 ··········</xccdf-1.2:Rule>67113 ··········</xccdf-1.2:Rule>
67114 ········</xccdf-1.2:Group>67114 ········</xccdf-1.2:Group>
67115 ······</xccdf-1.2:Group>67115 ······</xccdf-1.2:Group>
67116 ····</xccdf-1.2:Benchmark>67116 ····</xccdf-1.2:Benchmark>
67117 ··</ds:component>67117 ··</ds:component>
67118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-02-28T20:08:00">67118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-oval.xml"·timestamp="2025-03-01T22:08:00">
67119 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">67119 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
67120 ······<oval-def:generator>67120 ······<oval-def:generator>
67121 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>67121 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
67122 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>67122 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
67123 ········<oval:schema_version>5.11</oval:schema_version>67123 ········<oval:schema_version>5.11</oval:schema_version>
67124 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>67124 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
67125 ······</oval-def:generator>67125 ······</oval-def:generator>
Offset 84657, 5792 lines modifiedOffset 84657, 5446 lines modified
84657 ············</oval-def:arithmetic>84657 ············</oval-def:arithmetic>
84658 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>84658 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
84659 ··········</oval-def:arithmetic>84659 ··········</oval-def:arithmetic>
84660 ········</oval-def:local_variable>84660 ········</oval-def:local_variable>
84661 ······</oval-def:variables>84661 ······</oval-def:variables>
84662 ····</oval-def:oval_definitions>84662 ····</oval-def:oval_definitions>
84663 ··</ds:component>84663 ··</ds:component>
84664 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-02-28T20:08:00">84664 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu1804-ocil.xml"·timestamp="2025-03-01T22:08:00">
84665 ····<ocil:ocil>84665 ····<ocil:ocil>
84666 ······<ocil:generator>84666 ······<ocil:generator>
84667 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>84667 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
84668 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>84668 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
84669 ········<ocil:schema_version>2.0</ocil:schema_version>84669 ········<ocil:schema_version>2.0</ocil:schema_version>
84670 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>84670 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
84671 ······</ocil:generator>84671 ······</ocil:generator>
84672 ······<ocil:questionnaires>84672 ······<ocil:questionnaires>
84673 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1"> 
84674 ··········<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>84673 ········<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
 84674 ··········<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>
84675 ··········<ocil:actions>84675 ··········<ocil:actions>
84676 ············<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>84676 ············<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
84677 ··········</ocil:actions>84677 ··········</ocil:actions>
84678 ········</ocil:questionnaire>84678 ········</ocil:questionnaire>
84679 ········<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">84679 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
84680 ··········<ocil:title>Remove·Rsh·Trust·Files</ocil:title>84680 ··········<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
84681 ··········<ocil:actions>84681 ··········<ocil:actions>
84682 ············<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>84682 ············<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
84683 ··········</ocil:actions>84683 ··········</ocil:actions>
84684 ········</ocil:questionnaire>84684 ········</ocil:questionnaire>
84685 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">84685 ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
84686 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>84686 ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
84687 ··········<ocil:actions>84687 ··········<ocil:actions>
84688 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>84688 ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
84689 ··········</ocil:actions>84689 ··········</ocil:actions>
84690 ········</ocil:questionnaire>84690 ········</ocil:questionnaire>
84691 ········<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">84691 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
84692 ··········<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>84692 ··········<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
84693 ··········<ocil:actions>84693 ··········<ocil:actions>
84694 ············<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>84694 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
84695 ··········</ocil:actions>84695 ··········</ocil:actions>
84696 ········</ocil:questionnaire>84696 ········</ocil:questionnaire>
84697 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">84697 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
84698 ··········<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>84698 ··········<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
84699 ··········<ocil:actions>84699 ··········<ocil:actions>
84700 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>84700 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
84701 ··········</ocil:actions>84701 ··········</ocil:actions>
84702 ········</ocil:questionnaire>84702 ········</ocil:questionnaire>
84703 ········<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">84703 ········<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">
84704 ··········<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>84704 ··········<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>
84705 ··········<ocil:actions>84705 ··········<ocil:actions>
84706 ············<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>84706 ············<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>
84707 ··········</ocil:actions>84707 ··········</ocil:actions>
84708 ········</ocil:questionnaire>84708 ········</ocil:questionnaire>
84709 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">84709 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
84710 ··········<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>84710 ··········<ocil:title>Set·Password·Warning·Age</ocil:title>
84711 ··········<ocil:actions>84711 ··········<ocil:actions>
84712 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>84712 ············<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
84713 ··········</ocil:actions>84713 ··········</ocil:actions>
84714 ········</ocil:questionnaire>84714 ········</ocil:questionnaire>
84715 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">84715 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
84716 ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title>84716 ··········<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>
84717 ··········<ocil:actions>84717 ··········<ocil:actions>
84718 ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>84718 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
84719 ··········</ocil:actions>84719 ··········</ocil:actions>
84720 ········</ocil:questionnaire>84720 ········</ocil:questionnaire>
84721 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">84721 ········<ocil:questionnaire·id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">
84722 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>84722 ··········<ocil:title>Enable·the·NTP·Daemon</ocil:title>
84723 ··········<ocil:actions>84723 ··········<ocil:actions>
84724 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>84724 ············<ocil:test_action_ref>ocil:ssg-service_ntp_enabled_action:testaction:1</ocil:test_action_ref>
84725 ··········</ocil:actions>84725 ··········</ocil:actions>
84726 ········</ocil:questionnaire>84726 ········</ocil:questionnaire>
84727 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">84727 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
84728 ··········<ocil:title>Add·nodev·Option·to·/home</ocil:title>84728 ··········<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>
84729 ··········<ocil:actions>84729 ··········<ocil:actions>
84730 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>84730 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
84731 ··········</ocil:actions>84731 ··········</ocil:actions>
84732 ········</ocil:questionnaire>84732 ········</ocil:questionnaire>
84733 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">84733 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
84734 ··········<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>84734 ··········<ocil:title>Kernel·panic·timeout</ocil:title>
84735 ··········<ocil:actions>84735 ··········<ocil:actions>
84736 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>84736 ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>
84737 ··········</ocil:actions>84737 ··········</ocil:actions>
84738 ········</ocil:questionnaire>84738 ········</ocil:questionnaire>
84739 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">84739 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">
84740 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>84740 ··········<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>
84741 ··········<ocil:actions>84741 ··········<ocil:actions>
84742 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>84742 ············<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 736116/748408 bytes (98.36%) of diff not shown.
696 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
696 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
Ordering differences only
    
Offset 3, 5783 lines modifiedOffset 3, 5437 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
17 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>17 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>23 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>29 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>35 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>41 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
47 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>47 ······<ocil:title>Set·Password·Warning·Age</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>53 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>59 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-service_ntp_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
65 ······<ocil:title>Add·nodev·Option·to·/home</ocil:title>65 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
71 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>71 ······<ocil:title>Kernel·panic·timeout</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">
77 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>77 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1"> 
89 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1">
 89 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">
95 ······<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>95 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1">
107 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>107 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>113 ······<ocil:title>Verify·that·System·Executable·Directories·Have·Restrictive·Permissions</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
119 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>119 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1"> 
125 ······<ocil:title>Enable·Yama·support</ocil:title>124 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1">
 125 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
Max diff block lines reached; 699637/712228 bytes (98.23%) of diff not shown.
1.37 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
1.37 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2004-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2004-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·20.04·(Focal·Fossa)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2004:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_20-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·20.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·20.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 143123, 15 lines modifiedOffset 143123, 15 lines modified
143123 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>143123 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2004-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
143124 ············</xccdf-1.2:check>143124 ············</xccdf-1.2:check>
143125 ··········</xccdf-1.2:Rule>143125 ··········</xccdf-1.2:Rule>
143126 ········</xccdf-1.2:Group>143126 ········</xccdf-1.2:Group>
143127 ······</xccdf-1.2:Group>143127 ······</xccdf-1.2:Group>
143128 ····</xccdf-1.2:Benchmark>143128 ····</xccdf-1.2:Benchmark>
143129 ··</ds:component>143129 ··</ds:component>
143130 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-02-28T20:08:00">143130 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-oval.xml"·timestamp="2025-03-01T22:08:00">
143131 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">143131 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
143132 ······<oval-def:generator>143132 ······<oval-def:generator>
143133 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>143133 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
143134 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>143134 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
143135 ········<oval:schema_version>5.11</oval:schema_version>143135 ········<oval:schema_version>5.11</oval:schema_version>
143136 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>143136 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
143137 ······</oval-def:generator>143137 ······</oval-def:generator>
Offset 174684, 7207 lines modifiedOffset 174684, 7207 lines modified
174684 ············</oval-def:arithmetic>174684 ············</oval-def:arithmetic>
174685 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>174685 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
174686 ··········</oval-def:arithmetic>174686 ··········</oval-def:arithmetic>
174687 ········</oval-def:local_variable>174687 ········</oval-def:local_variable>
174688 ······</oval-def:variables>174688 ······</oval-def:variables>
174689 ····</oval-def:oval_definitions>174689 ····</oval-def:oval_definitions>
174690 ··</ds:component>174690 ··</ds:component>
174691 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-02-28T20:08:00">174691 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2004-ocil.xml"·timestamp="2025-03-01T22:08:00">
174692 ····<ocil:ocil>174692 ····<ocil:ocil>
174693 ······<ocil:generator>174693 ······<ocil:generator>
174694 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>174694 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
174695 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>174695 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
174696 ········<ocil:schema_version>2.0</ocil:schema_version>174696 ········<ocil:schema_version>2.0</ocil:schema_version>
174697 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>174697 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
174698 ······</ocil:generator>174698 ······</ocil:generator>
174699 ······<ocil:questionnaires>174699 ······<ocil:questionnaires>
174700 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> 
174701 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> 
174702 ··········<ocil:actions> 
174703 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> 
174704 ··········</ocil:actions> 
174705 ········</ocil:questionnaire> 
174706 ········<ocil:questionnaire·id="ocil:ssg-nftables_rules_permanent_ocil:questionnaire:1"> 
174707 ··········<ocil:title>Ensure·nftables·Rules·are·Permanent</ocil:title> 
174708 ··········<ocil:actions> 
174709 ············<ocil:test_action_ref>ocil:ssg-nftables_rules_permanent_action:testaction:1</ocil:test_action_ref> 
174710 ··········</ocil:actions> 
174711 ········</ocil:questionnaire> 
174712 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">174700 ········<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
 174701 ··········<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>
174713 ··········<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title> 
174714 ··········<ocil:actions> 
174715 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref> 
174716 ··········</ocil:actions> 
174717 ········</ocil:questionnaire> 
174718 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> 
174719 ··········<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title> 
174720 ··········<ocil:actions>174702 ··········<ocil:actions>
174721 ············<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>174703 ············<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
174722 ··········</ocil:actions>174704 ··········</ocil:actions>
174723 ········</ocil:questionnaire>174705 ········</ocil:questionnaire>
174724 ········<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"> 
174725 ··········<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>174706 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1">
 174707 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title>
174726 ··········<ocil:actions>174708 ··········<ocil:actions>
174727 ············<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>174709 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>
174728 ··········</ocil:actions>174710 ··········</ocil:actions>
174729 ········</ocil:questionnaire>174711 ········</ocil:questionnaire>
174730 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">174712 ········<ocil:questionnaire·id="ocil:ssg-package_pam_pwquality_installed_ocil:questionnaire:1">
174731 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>174713 ··········<ocil:title>Install·pam_pwquality·Package</ocil:title>
174732 ··········<ocil:actions>174714 ··········<ocil:actions>
174733 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>174715 ············<ocil:test_action_ref>ocil:ssg-package_pam_pwquality_installed_action:testaction:1</ocil:test_action_ref>
174734 ··········</ocil:actions>174716 ··········</ocil:actions>
174735 ········</ocil:questionnaire>174717 ········</ocil:questionnaire>
174736 ········<ocil:questionnaire·id="ocil:ssg-bios_enable_execution_restrictions_ocil:questionnaire:1">174718 ········<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">
174737 ··········<ocil:title>Enable·NX·or·XD·Support·in·the·BIOS</ocil:title>174719 ··········<ocil:title>Uninstall·rsync·Package</ocil:title>
174738 ··········<ocil:actions>174720 ··········<ocil:actions>
174739 ············<ocil:test_action_ref>ocil:ssg-bios_enable_execution_restrictions_action:testaction:1</ocil:test_action_ref>174721 ············<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>
174740 ··········</ocil:actions>174722 ··········</ocil:actions>
174741 ········</ocil:questionnaire>174723 ········</ocil:questionnaire>
174742 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1">174724 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
174743 ··········<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title>174725 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
174744 ··········<ocil:actions>174726 ··········<ocil:actions>
174745 ············<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>174727 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
174746 ··········</ocil:actions>174728 ··········</ocil:actions>
174747 ········</ocil:questionnaire>174729 ········</ocil:questionnaire>
174748 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> 
174749 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>174730 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">
 174731 ··········<ocil:title>Enable·different·security·models</ocil:title>
174750 ··········<ocil:actions>174732 ··········<ocil:actions>
174751 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>174733 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>
174752 ··········</ocil:actions>174734 ··········</ocil:actions>
174753 ········</ocil:questionnaire>174735 ········</ocil:questionnaire>
174754 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">174736 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
174755 ··········<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>174737 ··········<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>
174756 ··········<ocil:actions>174738 ··········<ocil:actions>
174757 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>174739 ············<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>
174758 ··········</ocil:actions>174740 ··········</ocil:actions>
174759 ········</ocil:questionnaire>174741 ········</ocil:questionnaire>
174760 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"> 
174761 ··········<ocil:title>Disable·mutable·hooks</ocil:title>174742 ········<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_user_ownership_ocil:questionnaire:1">
 174743 ··········<ocil:title>User·Initialization·Files·Must·Be·Owned·By·the·Primary·User</ocil:title>
174762 ··········<ocil:actions>174744 ··········<ocil:actions>
174763 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>174745 ············<ocil:test_action_ref>ocil:ssg-accounts_user_dot_user_ownership_action:testaction:1</ocil:test_action_ref>
174764 ··········</ocil:actions>174746 ··········</ocil:actions>
174765 ········</ocil:questionnaire>174747 ········</ocil:questionnaire>
174766 ········<ocil:questionnaire·id="ocil:ssg-ensure_pam_wheel_group_empty_ocil:questionnaire:1"> 
Max diff block lines reached; 1423928/1435336 bytes (99.21%) of diff not shown.
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
Ordering differences only
    
Offset 3, 7198 lines modifiedOffset 3, 7198 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-nftables_rules_permanent_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·nftables·Rules·are·Permanent</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-nftables_rules_permanent_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>
23 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"> 
29 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title> 
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Prevent·the·Use·of·Dictionary·Words</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_pam_pwquality_installed_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>23 ······<ocil:title>Install·pam_pwquality·Package</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_pam_pwquality_installed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-bios_enable_execution_restrictions_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">
47 ······<ocil:title>Enable·NX·or·XD·Support·in·the·BIOS</ocil:title>29 ······<ocil:title>Uninstall·rsync·Package</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-bios_enable_execution_restrictions_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
53 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title>35 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> 
59 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">
 41 ······<ocil:title>Enable·different·security·models</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
65 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>47 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"> 
71 ······<ocil:title>Disable·mutable·hooks</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_user_ownership_ocil:questionnaire:1">
 53 ······<ocil:title>User·Initialization·Files·Must·Be·Owned·By·the·Primary·User</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_user_ownership_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-ensure_pam_wheel_group_empty_ocil:questionnaire:1"> 
77 ······<ocil:title>Ensure·the·Group·Used·by·pam_wheel.so·Module·Exists·on·System·and·is·Empty</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">
 59 ······<ocil:title>Add·nosuid·Option·to·/dev/shm</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-ensure_pam_wheel_group_empty_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1">
83 ······<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>65 ······<ocil:title>Ensure·that·System·Accounts·Do·Not·Run·a·Shell·Upon·Login</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Permissions·on·cron.daily</ocil:title>71 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·clock_settime</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_tmp_ocil:questionnaire:1">
95 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>77 ······<ocil:title>Ensure·/var/tmp·Located·On·Separate·Partition</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_tmp_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·su</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_user_list_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·the·GNOME3·Login·User·List</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_user_list_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1">
 89 ······<ocil:title>Lock·Accounts·After·Failed·Password·Attempts</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-journald_forward_to_syslog_ocil:questionnaire:1">
113 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>95 ······<ocil:title>Ensure·journald·is·configured·to·send·logs·to·rsyslog</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-journald_forward_to_syslog_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">
 101 ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1360559/1372210 bytes (99.15%) of diff not shown.
1.43 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
1.43 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2204-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2204-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·22.04·(Jammy·Jellyfish)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2204:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_22-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·22.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·22.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 148842, 15 lines modifiedOffset 148842, 15 lines modified
148842 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>148842 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2204-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
148843 ············</xccdf-1.2:check>148843 ············</xccdf-1.2:check>
148844 ··········</xccdf-1.2:Rule>148844 ··········</xccdf-1.2:Rule>
148845 ········</xccdf-1.2:Group>148845 ········</xccdf-1.2:Group>
148846 ······</xccdf-1.2:Group>148846 ······</xccdf-1.2:Group>
148847 ····</xccdf-1.2:Benchmark>148847 ····</xccdf-1.2:Benchmark>
148848 ··</ds:component>148848 ··</ds:component>
148849 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-02-28T20:08:00">148849 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-oval.xml"·timestamp="2025-03-01T22:08:00">
148850 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">148850 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
148851 ······<oval-def:generator>148851 ······<oval-def:generator>
148852 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>148852 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
148853 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>148853 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
148854 ········<oval:schema_version>5.11</oval:schema_version>148854 ········<oval:schema_version>5.11</oval:schema_version>
148855 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>148855 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
148856 ······</oval-def:generator>148856 ······</oval-def:generator>
Offset 181748, 6537 lines modifiedOffset 181748, 6537 lines modified
181748 ············</oval-def:arithmetic>181748 ············</oval-def:arithmetic>
181749 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>181749 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
181750 ··········</oval-def:arithmetic>181750 ··········</oval-def:arithmetic>
181751 ········</oval-def:local_variable>181751 ········</oval-def:local_variable>
181752 ······</oval-def:variables>181752 ······</oval-def:variables>
181753 ····</oval-def:oval_definitions>181753 ····</oval-def:oval_definitions>
181754 ··</ds:component>181754 ··</ds:component>
181755 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-02-28T20:08:00">181755 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2204-ocil.xml"·timestamp="2025-03-01T22:08:00">
181756 ····<ocil:ocil>181756 ····<ocil:ocil>
181757 ······<ocil:generator>181757 ······<ocil:generator>
181758 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>181758 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
181759 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>181759 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
181760 ········<ocil:schema_version>2.0</ocil:schema_version>181760 ········<ocil:schema_version>2.0</ocil:schema_version>
181761 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>181761 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
181762 ······</ocil:generator>181762 ······</ocil:generator>
181763 ······<ocil:questionnaires>181763 ······<ocil:questionnaires>
181764 ········<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">181764 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
 181765 ··········<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
181765 ··········<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title> 
181766 ··········<ocil:actions> 
181767 ············<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref> 
181768 ··········</ocil:actions> 
181769 ········</ocil:questionnaire> 
181770 ········<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1"> 
181771 ··········<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title> 
181772 ··········<ocil:actions>181766 ··········<ocil:actions>
181773 ············<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>181767 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
181774 ··········</ocil:actions>181768 ··········</ocil:actions>
181775 ········</ocil:questionnaire>181769 ········</ocil:questionnaire>
181776 ········<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">181770 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
181777 ··········<ocil:title>Verify·iptables·Enabled</ocil:title>181771 ··········<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>
181778 ··········<ocil:actions>181772 ··········<ocil:actions>
181779 ············<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>181773 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
181780 ··········</ocil:actions>181774 ··········</ocil:actions>
181781 ········</ocil:questionnaire>181775 ········</ocil:questionnaire>
181782 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">181776 ········<ocil:questionnaire·id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1">
181783 ··········<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>181777 ··········<ocil:title>Allow·Only·SSH·Protocol·2</ocil:title>
181784 ··········<ocil:actions>181778 ··········<ocil:actions>
181785 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>181779 ············<ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref>
181786 ··········</ocil:actions>181780 ··········</ocil:actions>
181787 ········</ocil:questionnaire>181781 ········</ocil:questionnaire>
181788 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">181782 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">
181789 ··········<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>181783 ··········<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>
181790 ··········<ocil:actions>181784 ··········<ocil:actions>
181791 ············<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>181785 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>
181792 ··········</ocil:actions>181786 ··········</ocil:actions>
181793 ········</ocil:questionnaire>181787 ········</ocil:questionnaire>
181794 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1"> 
181795 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title>181788 ········<ocil:questionnaire·id="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1">
 181789 ··········<ocil:title>System·Audit·Logs·Must·Be·Group·Owned·By·Root</ocil:title>
181796 ··········<ocil:actions>181790 ··········<ocil:actions>
181797 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>181791 ············<ocil:test_action_ref>ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
181798 ··········</ocil:actions>181792 ··········</ocil:actions>
181799 ········</ocil:questionnaire>181793 ········</ocil:questionnaire>
181800 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1">181794 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
181801 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers.d/</ocil:title>181795 ··········<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
181802 ··········<ocil:actions>181796 ··········<ocil:actions>
181803 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>181797 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
181804 ··········</ocil:actions>181798 ··········</ocil:actions>
181805 ········</ocil:questionnaire>181799 ········</ocil:questionnaire>
181806 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_allow_ocil:questionnaire:1">181800 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
181807 ··········<ocil:title>Verify·User·Who·Owns·/etc/cron.allow·file</ocil:title>181801 ··········<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
181808 ··········<ocil:actions>181802 ··········<ocil:actions>
181809 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_allow_action:testaction:1</ocil:test_action_ref>181803 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
181810 ··········</ocil:actions>181804 ··········</ocil:actions>
181811 ········</ocil:questionnaire>181805 ········</ocil:questionnaire>
181812 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">181806 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
181813 ··········<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>181807 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
181814 ··········<ocil:actions>181808 ··········<ocil:actions>
181815 ············<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>181809 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
181816 ··········</ocil:actions>181810 ··········</ocil:actions>
181817 ········</ocil:questionnaire>181811 ········</ocil:questionnaire>
181818 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">181812 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">
181819 ··········<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>181813 ··········<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·User</ocil:title>
181820 ··········<ocil:actions>181814 ··········<ocil:actions>
181821 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>181815 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>
181822 ··········</ocil:actions>181816 ··········</ocil:actions>
181823 ········</ocil:questionnaire>181817 ········</ocil:questionnaire>
181824 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">181818 ········<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">
181825 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>181819 ··········<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>
181826 ··········<ocil:actions>181820 ··········<ocil:actions>
181827 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>181821 ············<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>
181828 ··········</ocil:actions>181822 ··········</ocil:actions>
181829 ········</ocil:questionnaire>181823 ········</ocil:questionnaire>
181830 ········<ocil:questionnaire·id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">181824 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">
181831 ··········<ocil:title>Uninstall·Samba·Package</ocil:title>181825 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
181832 ··········<ocil:actions>181826 ··········<ocil:actions>
Max diff block lines reached; 1482651/1494786 bytes (99.19%) of diff not shown.
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
Ordering differences only
    
Offset 3, 6528 lines modifiedOffset 3, 6528 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>
11 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1"> 
17 ······<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
23 ······<ocil:title>Verify·iptables·Enabled</ocil:title>17 ······<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>23 ······<ocil:title>Allow·Only·SSH·Protocol·2</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">
35 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>29 ······<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1">
 35 ······<ocil:title>System·Audit·Logs·Must·Be·Group·Owned·By·Root</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions·-·/etc/sudoers.d/</ocil:title>41 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_allow_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·User·Who·Owns·/etc/cron.allow·file</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_allow_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
59 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>53 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">
65 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>59 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·User</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">
71 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>65 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">
77 ······<ocil:title>Uninstall·Samba·Package</ocil:title>71 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_samba_removed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1"> 
83 ······<ocil:title>Add·nodev·Option·to·/dev/shm</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">
 77 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-set_ufw_loopback_traffic_ocil:questionnaire:1"> 
89 ······<ocil:title>Set·UFW·Loopback·Traffic</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 83 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-set_ufw_loopback_traffic_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_system_journal_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Group·Who·Owns·the·system·journal</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_system_journal_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_iptables-persistent_removed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_session_events_utmp_ocil:questionnaire:1">
101 ······<ocil:title>Remove·iptables-persistent·Package</ocil:title>95 ······<ocil:title>Record·Attempts·to·Alter·Process·and·Session·Initiation·Information·utmp</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_iptables-persistent_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_session_events_utmp_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_audit_auditd_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_noexec_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Permissions·on·/etc/audit/auditd.conf</ocil:title>101 ······<ocil:title>Add·noexec·Option·to·/var/log</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_auditd_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_noexec_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1"> 
113 ······<ocil:title>Use·Only·FIPS·140-2·Validated·Ciphers</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">
 107 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_ordered_stig_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_kmod_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_filecreatemode_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·kmod</ocil:title>113 ······<ocil:title>Ensure·rsyslog·Default·File·Permissions·Configured</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_kmod_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_filecreatemode_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 1416494/1429098 bytes (99.12%) of diff not shown.
929 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
929 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ubuntu2404-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ubuntu2404-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">28 ······<cpe-dict:cpe-item·name="cpe:/o:canonical:ubuntu_linux:24.04::~~lts~~~">
29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Ubuntu·release·24.04·(Noble·Numbat)</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml">oval:ssg-installed_OS_is_ubuntu2404:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UBUNTU_24-04"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·24.04</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of40 configuration·settings·for·Ubuntu·24.04.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 102298, 15 lines modifiedOffset 102298, 15 lines modified
102298 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>102298 ··············<xccdf-1.2:check-content-ref·href="ssg-ubuntu2404-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
102299 ············</xccdf-1.2:check>102299 ············</xccdf-1.2:check>
102300 ··········</xccdf-1.2:Rule>102300 ··········</xccdf-1.2:Rule>
102301 ········</xccdf-1.2:Group>102301 ········</xccdf-1.2:Group>
102302 ······</xccdf-1.2:Group>102302 ······</xccdf-1.2:Group>
102303 ····</xccdf-1.2:Benchmark>102303 ····</xccdf-1.2:Benchmark>
102304 ··</ds:component>102304 ··</ds:component>
102305 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-02-28T20:08:00">102305 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-oval.xml"·timestamp="2025-03-01T22:08:00">
102306 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">102306 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
102307 ······<oval-def:generator>102307 ······<oval-def:generator>
102308 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>102308 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
102309 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>102309 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
102310 ········<oval:schema_version>5.11</oval:schema_version>102310 ········<oval:schema_version>5.11</oval:schema_version>
102311 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>102311 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
102312 ······</oval-def:generator>102312 ······</oval-def:generator>
Offset 123597, 9712 lines modifiedOffset 123597, 9712 lines modified
123597 ············</oval-def:arithmetic>123597 ············</oval-def:arithmetic>
123598 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>123598 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
123599 ··········</oval-def:arithmetic>123599 ··········</oval-def:arithmetic>
123600 ········</oval-def:local_variable>123600 ········</oval-def:local_variable>
123601 ······</oval-def:variables>123601 ······</oval-def:variables>
123602 ····</oval-def:oval_definitions>123602 ····</oval-def:oval_definitions>
123603 ··</ds:component>123603 ··</ds:component>
123604 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-02-28T20:08:00">123604 ··<ds:component·id="scap_org.open-scap_comp_ssg-ubuntu2404-ocil.xml"·timestamp="2025-03-01T22:08:00">
123605 ····<ocil:ocil>123605 ····<ocil:ocil>
123606 ······<ocil:generator>123606 ······<ocil:generator>
123607 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>123607 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
123608 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>123608 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
123609 ········<ocil:schema_version>2.0</ocil:schema_version>123609 ········<ocil:schema_version>2.0</ocil:schema_version>
123610 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>123610 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
123611 ······</ocil:generator>123611 ······</ocil:generator>
123612 ······<ocil:questionnaires>123612 ······<ocil:questionnaires>
123613 ········<ocil:questionnaire·id="ocil:ssg-file_owner_at_deny_ocil:questionnaire:1"> 
123614 ··········<ocil:title>Verify·User·Who·Owns·/etc/at.deny·file</ocil:title> 
123615 ··········<ocil:actions> 
123616 ············<ocil:test_action_ref>ocil:ssg-file_owner_at_deny_action:testaction:1</ocil:test_action_ref> 
123617 ··········</ocil:actions> 
123618 ········</ocil:questionnaire> 
123619 ········<ocil:questionnaire·id="ocil:ssg-service_squid_disabled_ocil:questionnaire:1"> 
123620 ··········<ocil:title>Disable·Squid</ocil:title> 
123621 ··········<ocil:actions> 
123622 ············<ocil:test_action_ref>ocil:ssg-service_squid_disabled_action:testaction:1</ocil:test_action_ref> 
123623 ··········</ocil:actions> 
123624 ········</ocil:questionnaire> 
123625 ········<ocil:questionnaire·id="ocil:ssg-package_avahi_removed_ocil:questionnaire:1">123613 ········<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
123626 ··········<ocil:title>Uninstall·avahi·Server·Package</ocil:title>123614 ··········<ocil:title>Install·the·cron·service</ocil:title>
123627 ··········<ocil:actions> 
123628 ············<ocil:test_action_ref>ocil:ssg-package_avahi_removed_action:testaction:1</ocil:test_action_ref> 
123629 ··········</ocil:actions> 
123630 ········</ocil:questionnaire> 
123631 ········<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1"> 
123632 ··········<ocil:title>Disable·Network·File·System·(nfs)</ocil:title> 
123633 ··········<ocil:actions>123615 ··········<ocil:actions>
123634 ············<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>123616 ············<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
123635 ··········</ocil:actions>123617 ··········</ocil:actions>
123636 ········</ocil:questionnaire>123618 ········</ocil:questionnaire>
123637 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">123619 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
123638 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>123620 ··········<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
123639 ··········<ocil:actions>123621 ··········<ocil:actions>
123640 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>123622 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
123641 ··········</ocil:actions>123623 ··········</ocil:actions>
123642 ········</ocil:questionnaire>123624 ········</ocil:questionnaire>
123643 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">123625 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
123644 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>123626 ··········<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
123645 ··········<ocil:actions>123627 ··········<ocil:actions>
123646 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>123628 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
123647 ··········</ocil:actions>123629 ··········</ocil:actions>
123648 ········</ocil:questionnaire>123630 ········</ocil:questionnaire>
123649 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">123631 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
123650 ··········<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>123632 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>
123651 ··········<ocil:actions>123633 ··········<ocil:actions>
123652 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>123634 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
123653 ··········</ocil:actions>123635 ··········</ocil:actions>
123654 ········</ocil:questionnaire>123636 ········</ocil:questionnaire>
123655 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">123637 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1">
123656 ··········<ocil:title>Add·nodev·Option·to·/home</ocil:title>123638 ··········<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·faillock</ocil:title>
123657 ··········<ocil:actions>123639 ··········<ocil:actions>
123658 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>123640 ············<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_faillock_action:testaction:1</ocil:test_action_ref>
123659 ··········</ocil:actions>123641 ··········</ocil:actions>
123660 ········</ocil:questionnaire>123642 ········</ocil:questionnaire>
123661 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> 
123662 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>123643 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_security_opasswd_old_ocil:questionnaire:1">
 123644 ··········<ocil:title>Verify·Group·Who·Owns·/etc/security/opasswd.old·File</ocil:title>
123663 ··········<ocil:actions>123645 ··········<ocil:actions>
123664 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>123646 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_security_opasswd_old_action:testaction:1</ocil:test_action_ref>
123665 ··········</ocil:actions>123647 ··········</ocil:actions>
123666 ········</ocil:questionnaire>123648 ········</ocil:questionnaire>
123667 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">123649 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1">
123668 ··········<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>123650 ··········<ocil:title>Disable·GNOME3·Automounting</ocil:title>
123669 ··········<ocil:actions>123651 ··········<ocil:actions>
123670 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>123652 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_action:testaction:1</ocil:test_action_ref>
123671 ··········</ocil:actions>123653 ··········</ocil:actions>
123672 ········</ocil:questionnaire>123654 ········</ocil:questionnaire>
123673 ········<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">123655 ········<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">
123674 ··········<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>123656 ··········<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>
123675 ··········<ocil:actions>123657 ··········<ocil:actions>
123676 ············<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>123658 ············<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>
123677 ··········</ocil:actions>123659 ··········</ocil:actions>
123678 ········</ocil:questionnaire>123660 ········</ocil:questionnaire>
123679 ········<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">123661 ········<ocil:questionnaire·id="ocil:ssg-package_ftp_removed_ocil:questionnaire:1">
123680 ··········<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title>123662 ··········<ocil:title>Remove·ftp·Package</ocil:title>
123681 ··········<ocil:actions>123663 ··········<ocil:actions>
123682 ············<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>123664 ············<ocil:test_action_ref>ocil:ssg-package_ftp_removed_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 939877/951227 bytes (98.81%) of diff not shown.
886 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
886 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
Ordering differences only
    
Offset 3, 9694 lines modifiedOffset 3, 9694 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_at_deny_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·User·Who·Owns·/etc/at.deny·file</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_at_deny_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-service_squid_disabled_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·Squid</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-service_squid_disabled_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-package_avahi_removed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
23 ······<ocil:title>Uninstall·avahi·Server·Package</ocil:title>11 ······<ocil:title>Install·the·cron·service</ocil:title>
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-package_avahi_removed_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·Network·File·System·(nfs)</ocil:title> 
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
35 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>17 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> 
41 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
47 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>29 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1"> 
53 ······<ocil:title>Add·nodev·Option·to·/home</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1">
 35 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·faillock</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_faillock_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"> 
59 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_security_opasswd_old_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·Group·Who·Owns·/etc/security/opasswd.old·File</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_security_opasswd_old_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1"> 
65 ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·GNOME3·Automounting</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>53 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_ftp_removed_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title>59 ······<ocil:title>Remove·ftp·Package</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_ftp_removed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1"> 
83 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·clock_settime</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>71 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-package_systemd-journal-remote_installed_ocil:questionnaire:1">
 77 ······<ocil:title>Install·systemd-journal-remote·Package</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_systemd-journal-remote_installed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
101 ······<ocil:title>Verify·ownership·of·System·Login·Banner</ocil:title>83 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>89 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_user_ownership_ocil:questionnaire:1">
 95 ······<ocil:title>User·Initialization·Files·Must·Be·Owned·By·the·Primary·User</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_user_ownership_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>101 ······<ocil:title>Uninstall·vsftpd·Package</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
Max diff block lines reached; 895993/907402 bytes (98.74%) of diff not shown.
3.73 MB
ssg-debian_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··1230356·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··1230204·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
3.73 MB
data.tar.xz
3.73 MB
data.tar
733 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
733 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian11-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian11-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">28 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:11">
29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·11</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml">oval:ssg-installed_OS_is_debian11:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-11"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·11</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Debian·11.·It·is·a·rendering·of40 configuration·settings·for·Debian·11.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 76227, 15 lines modifiedOffset 76227, 15 lines modified
76227 ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>76227 ··············<xccdf-1.2:check-content-ref·href="ssg-debian11-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
76228 ············</xccdf-1.2:check>76228 ············</xccdf-1.2:check>
76229 ··········</xccdf-1.2:Rule>76229 ··········</xccdf-1.2:Rule>
76230 ········</xccdf-1.2:Group>76230 ········</xccdf-1.2:Group>
76231 ······</xccdf-1.2:Group>76231 ······</xccdf-1.2:Group>
76232 ····</xccdf-1.2:Benchmark>76232 ····</xccdf-1.2:Benchmark>
76233 ··</ds:component>76233 ··</ds:component>
76234 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-02-28T20:08:00">76234 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-oval.xml"·timestamp="2025-03-01T22:08:00">
76235 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">76235 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
76236 ······<oval-def:generator>76236 ······<oval-def:generator>
76237 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>76237 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
76238 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>76238 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
76239 ········<oval:schema_version>5.11</oval:schema_version>76239 ········<oval:schema_version>5.11</oval:schema_version>
76240 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>76240 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
76241 ······</oval-def:generator>76241 ······</oval-def:generator>
Offset 93180, 2572 lines modifiedOffset 93180, 2572 lines modified
93180 ············</oval-def:arithmetic>93180 ············</oval-def:arithmetic>
93181 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>93181 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
93182 ··········</oval-def:arithmetic>93182 ··········</oval-def:arithmetic>
93183 ········</oval-def:local_variable>93183 ········</oval-def:local_variable>
93184 ······</oval-def:variables>93184 ······</oval-def:variables>
93185 ····</oval-def:oval_definitions>93185 ····</oval-def:oval_definitions>
93186 ··</ds:component>93186 ··</ds:component>
93187 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-02-28T20:08:00">93187 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian11-ocil.xml"·timestamp="2025-03-01T22:08:00">
93188 ····<ocil:ocil>93188 ····<ocil:ocil>
93189 ······<ocil:generator>93189 ······<ocil:generator>
93190 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>93190 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
93191 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>93191 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
93192 ········<ocil:schema_version>2.0</ocil:schema_version>93192 ········<ocil:schema_version>2.0</ocil:schema_version>
93193 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>93193 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
93194 ······</ocil:generator>93194 ······</ocil:generator>
93195 ······<ocil:questionnaires>93195 ······<ocil:questionnaires>
93196 ········<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">93196 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1">
93197 ··········<ocil:title>Disable·snmpd·Service</ocil:title>93197 ··········<ocil:title>Disable·mutable·hooks</ocil:title>
93198 ··········<ocil:actions>93198 ··········<ocil:actions>
93199 ············<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>93199 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>
93200 ··········</ocil:actions>93200 ··········</ocil:actions>
93201 ········</ocil:questionnaire>93201 ········</ocil:questionnaire>
93202 ········<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">93202 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1">
93203 ··········<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title>93203 ··········<ocil:title>Restrict·unprivileged·access·to·the·kernel·syslog</ocil:title>
93204 ··········<ocil:actions>93204 ··········<ocil:actions>
93205 ············<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>93205 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1</ocil:test_action_ref>
93206 ··········</ocil:actions>93206 ··········</ocil:actions>
93207 ········</ocil:questionnaire>93207 ········</ocil:questionnaire>
93208 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1"> 
93209 ··········<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title>93208 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
 93209 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
93210 ··········<ocil:actions>93210 ··········<ocil:actions>
93211 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>93211 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
93212 ··········</ocil:actions>93212 ··········</ocil:actions>
93213 ········</ocil:questionnaire>93213 ········</ocil:questionnaire>
93214 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> 
93215 ··········<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>93214 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">
 93215 ··········<ocil:title>Disable·the·IPv6·protocol</ocil:title>
93216 ··········<ocil:actions>93216 ··········<ocil:actions>
93217 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>93217 ············<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>
93218 ··········</ocil:actions>93218 ··········</ocil:actions>
93219 ········</ocil:questionnaire>93219 ········</ocil:questionnaire>
93220 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">93220 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
93221 ··········<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>93221 ··········<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
93222 ··········<ocil:actions>93222 ··········<ocil:actions>
93223 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>93223 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
93224 ··········</ocil:actions>93224 ··········</ocil:actions>
93225 ········</ocil:questionnaire>93225 ········</ocil:questionnaire>
93226 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">93226 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
93227 ··········<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>93227 ··········<ocil:title>Enable·Yama·support</ocil:title>
93228 ··········<ocil:actions>93228 ··········<ocil:actions>
93229 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>93229 ············<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>
93230 ··········</ocil:actions>93230 ··········</ocil:actions>
93231 ········</ocil:questionnaire>93231 ········</ocil:questionnaire>
93232 ········<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">93232 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
93233 ··········<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>93233 ··········<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
93234 ··········<ocil:actions>93234 ··········<ocil:actions>
93235 ············<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>93235 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
93236 ··········</ocil:actions>93236 ··········</ocil:actions>
93237 ········</ocil:questionnaire>93237 ········</ocil:questionnaire>
93238 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1"> 
93239 ··········<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>93238 ········<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
 93239 ··········<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>
93240 ··········<ocil:actions>93240 ··········<ocil:actions>
93241 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>93241 ············<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
93242 ··········</ocil:actions>93242 ··········</ocil:actions>
93243 ········</ocil:questionnaire>93243 ········</ocil:questionnaire>
93244 ········<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">93244 ········<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
93245 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>93245 ··········<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>
93246 ··········<ocil:actions>93246 ··········<ocil:actions>
93247 ············<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>93247 ············<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
93248 ··········</ocil:actions>93248 ··········</ocil:actions>
93249 ········</ocil:questionnaire>93249 ········</ocil:questionnaire>
93250 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">93250 ········<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
93251 ··········<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>93251 ··········<ocil:title>The·Chrony·package·is·installed</ocil:title>
93252 ··········<ocil:actions>93252 ··········<ocil:actions>
93253 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>93253 ············<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
93254 ··········</ocil:actions>93254 ··········</ocil:actions>
93255 ········</ocil:questionnaire>93255 ········</ocil:questionnaire>
93256 ········<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">93256 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
93257 ··········<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>93257 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
93258 ··········<ocil:actions>93258 ··········<ocil:actions>
93259 ············<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>93259 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
93260 ··········</ocil:actions>93260 ··········</ocil:actions>
93261 ········</ocil:questionnaire>93261 ········</ocil:questionnaire>
93262 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">93262 ········<ocil:questionnaire·id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">
93263 ··········<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>93263 ··········<ocil:title>Enable·the·NTP·Daemon</ocil:title>
Max diff block lines reached; 738877/750748 bytes (98.42%) of diff not shown.
698 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
698 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
Ordering differences only
    
Offset 3, 2563 lines modifiedOffset 3, 2563 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1">
11 ······<ocil:title>Disable·snmpd·Service</ocil:title>11 ······<ocil:title>Disable·mutable·hooks</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1">
17 ······<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title>17 ······<ocil:title>Restrict·unprivileged·access·to·the·kernel·syslog</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
 23 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">
 29 ······<ocil:title>Disable·the·IPv6·protocol</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
35 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>35 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>41 ······<ocil:title>Enable·Yama·support</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>47 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
 53 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>59 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
65 ······<ocil:title>Sign·kernel·modules·with·SHA-512</ocil:title>65 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>71 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">
77 ······<ocil:title>Record·Events·that·Modify·User/Group·Information</ocil:title>77 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-service_ntp_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_lastlog_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">
83 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·lastlog</ocil:title>83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_lastlog_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">
89 ······<ocil:title>Avoid·speculative·indirect·branches·in·kernel</ocil:title>89 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_retpoline_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_ocil:questionnaire:1">
95 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>95 ······<ocil:title>Ensure·/var·Located·On·Separate·Partition</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1">
101 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>101 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1"> 
107 ······<ocil:title>Disable·support·for·/proc/kkcore</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_num_logs_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·auditd·Number·of·Logs·Retained</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_proc_kcore_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_num_logs_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">
113 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>113 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">
119 ······<ocil:title>Enable·Public·Key·Authentication</ocil:title>119 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1">
125 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>125 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>
Max diff block lines reached; 702131/714774 bytes (98.23%) of diff not shown.
1.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
1.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-debian12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-debian12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-oval-definitions-bookworm.xml.bz2"·xlink:href="https://www.debian.org/security/oval/oval-definitions-bookworm.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:debian:debian_linux:12">
31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Debian·Linux·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml">oval:ssg-installed_OS_is_debian12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_DEBIAN-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Debian·12</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Debian·12.·It·is·a·rendering·of42 configuration·settings·for·Debian·12.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 274, 23 lines modifiedOffset 274, 23 lines modified
274 ··········</cpe-lang:logical-test>274 ··········</cpe-lang:logical-test>
275 ········</cpe-lang:platform>275 ········</cpe-lang:platform>
276 ········<cpe-lang:platform·id="package_bash">276 ········<cpe-lang:platform·id="package_bash">
277 ··········<cpe-lang:logical-test·operator="AND"·negate="false">277 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
278 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>278 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
279 ··········</cpe-lang:logical-test>279 ··········</cpe-lang:logical-test>
280 ········</cpe-lang:platform>280 ········</cpe-lang:platform>
281 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">281 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
282 ··········<cpe-lang:logical-test·operator="AND"·negate="false">282 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
283 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>283 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
284 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
285 ··········</cpe-lang:logical-test>284 ··········</cpe-lang:logical-test>
286 ········</cpe-lang:platform>285 ········</cpe-lang:platform>
287 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">286 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
288 ··········<cpe-lang:logical-test·operator="AND"·negate="false">287 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
289 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>288 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 289 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
290 ··········</cpe-lang:logical-test>290 ··········</cpe-lang:logical-test>
291 ········</cpe-lang:platform>291 ········</cpe-lang:platform>
292 ········<cpe-lang:platform·id="package_shadow-utils">292 ········<cpe-lang:platform·id="package_shadow-utils">
293 ··········<cpe-lang:logical-test·operator="AND"·negate="false">293 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
294 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>294 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
295 ··········</cpe-lang:logical-test>295 ··········</cpe-lang:logical-test>
296 ········</cpe-lang:platform>296 ········</cpe-lang:platform>
Offset 110245, 15 lines modifiedOffset 110245, 15 lines modified
110245 ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>110245 ··············<xccdf-1.2:check-content-ref·href="ssg-debian12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
110246 ············</xccdf-1.2:check>110246 ············</xccdf-1.2:check>
110247 ··········</xccdf-1.2:Rule>110247 ··········</xccdf-1.2:Rule>
110248 ········</xccdf-1.2:Group>110248 ········</xccdf-1.2:Group>
110249 ······</xccdf-1.2:Group>110249 ······</xccdf-1.2:Group>
110250 ····</xccdf-1.2:Benchmark>110250 ····</xccdf-1.2:Benchmark>
110251 ··</ds:component>110251 ··</ds:component>
110252 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-02-28T20:08:00">110252 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-oval.xml"·timestamp="2025-03-01T22:08:00">
110253 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">110253 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
110254 ······<oval-def:generator>110254 ······<oval-def:generator>
110255 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>110255 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
110256 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>110256 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
110257 ········<oval:schema_version>5.11</oval:schema_version>110257 ········<oval:schema_version>5.11</oval:schema_version>
110258 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>110258 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
110259 ······</oval-def:generator>110259 ······</oval-def:generator>
Offset 140530, 3850 lines modifiedOffset 140530, 3850 lines modified
140530 ············</oval-def:arithmetic>140530 ············</oval-def:arithmetic>
140531 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>140531 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
140532 ··········</oval-def:arithmetic>140532 ··········</oval-def:arithmetic>
140533 ········</oval-def:local_variable>140533 ········</oval-def:local_variable>
140534 ······</oval-def:variables>140534 ······</oval-def:variables>
140535 ····</oval-def:oval_definitions>140535 ····</oval-def:oval_definitions>
140536 ··</ds:component>140536 ··</ds:component>
140537 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-02-28T20:08:00">140537 ··<ds:component·id="scap_org.open-scap_comp_ssg-debian12-ocil.xml"·timestamp="2025-03-01T22:08:00">
140538 ····<ocil:ocil>140538 ····<ocil:ocil>
140539 ······<ocil:generator>140539 ······<ocil:generator>
140540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>140540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
140541 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>140541 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
140542 ········<ocil:schema_version>2.0</ocil:schema_version>140542 ········<ocil:schema_version>2.0</ocil:schema_version>
140543 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>140543 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
140544 ······</ocil:generator>140544 ······</ocil:generator>
140545 ······<ocil:questionnaires>140545 ······<ocil:questionnaires>
140546 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> 
140547 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>140546 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">
 140547 ··········<ocil:title>Specify·module·signing·key·to·use</ocil:title>
140548 ··········<ocil:actions>140548 ··········<ocil:actions>
140549 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>140549 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>
140550 ··········</ocil:actions>140550 ··········</ocil:actions>
140551 ········</ocil:questionnaire>140551 ········</ocil:questionnaire>
140552 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">140552 ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1">
140553 ··········<ocil:title>Enable·module·signature·verification</ocil:title>140553 ··········<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>
140554 ··········<ocil:actions>140554 ··········<ocil:actions>
140555 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>140555 ············<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>
140556 ··········</ocil:actions>140556 ··········</ocil:actions>
140557 ········</ocil:questionnaire>140557 ········</ocil:questionnaire>
140558 ········<ocil:questionnaire·id="ocil:ssg-grub2_page_alloc_shuffle_argument_ocil:questionnaire:1"> 
140559 ··········<ocil:title>Enable·randomization·of·the·page·allocator</ocil:title>140558 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
 140559 ··········<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>
140560 ··········<ocil:actions>140560 ··········<ocil:actions>
140561 ············<ocil:test_action_ref>ocil:ssg-grub2_page_alloc_shuffle_argument_action:testaction:1</ocil:test_action_ref>140561 ············<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
140562 ··········</ocil:actions>140562 ··········</ocil:actions>
140563 ········</ocil:questionnaire>140563 ········</ocil:questionnaire>
140564 ········<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">140564 ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
140565 ··········<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title>140565 ··········<ocil:title>Enable·systemd-journald·Service</ocil:title>
140566 ··········<ocil:actions>140566 ··········<ocil:actions>
140567 ············<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref>140567 ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
140568 ··········</ocil:actions>140568 ··········</ocil:actions>
140569 ········</ocil:questionnaire>140569 ········</ocil:questionnaire>
140570 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">140570 ········<ocil:questionnaire·id="ocil:ssg-mount_option_srv_nosuid_ocil:questionnaire:1">
140571 ··········<ocil:title>Disable·TIPC·Support</ocil:title>140571 ··········<ocil:title>Add·nosuid·Option·to·/srv</ocil:title>
140572 ··········<ocil:actions>140572 ··········<ocil:actions>
140573 ············<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>140573 ············<ocil:test_action_ref>ocil:ssg-mount_option_srv_nosuid_action:testaction:1</ocil:test_action_ref>
140574 ··········</ocil:actions>140574 ··········</ocil:actions>
140575 ········</ocil:questionnaire>140575 ········</ocil:questionnaire>
140576 ········<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">140576 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
140577 ··········<ocil:title>Uninstall·talk·Package</ocil:title>140577 ··········<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
140578 ··········<ocil:actions>140578 ··········<ocil:actions>
140579 ············<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>140579 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
140580 ··········</ocil:actions>140580 ··········</ocil:actions>
140581 ········</ocil:questionnaire>140581 ········</ocil:questionnaire>
140582 ········<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1">140582 ········<ocil:questionnaire·id="ocil:ssg-dir_system_commands_group_root_owned_ocil:questionnaire:1">
140583 ··········<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title>140583 ··········<ocil:title>Verify·that·system·commands·directories·have·root·as·a·group·owner</ocil:title>
140584 ··········<ocil:actions>140584 ··········<ocil:actions>
140585 ············<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1</ocil:test_action_ref>140585 ············<ocil:test_action_ref>ocil:ssg-dir_system_commands_group_root_owned_action:testaction:1</ocil:test_action_ref>
140586 ··········</ocil:actions>140586 ··········</ocil:actions>
140587 ········</ocil:questionnaire>140587 ········</ocil:questionnaire>
140588 ········<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">140588 ········<ocil:questionnaire·id="ocil:ssg-aide_periodic_checking_systemd_timer_ocil:questionnaire:1">
140589 ··········<ocil:title>Ensure·nss-tools·is·installed</ocil:title>140589 ··········<ocil:title>Configure·Systemd·Timer·Execution·of·AIDE</ocil:title>
Max diff block lines reached; 1240134/1252084 bytes (99.05%) of diff not shown.
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
Ordering differences only
    
Offset 3, 3841 lines modifiedOffset 3, 3841 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"> 
11 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">
 11 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1">
17 ······<ocil:title>Enable·module·signature·verification</ocil:title>17 ······<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_page_alloc_shuffle_argument_ocil:questionnaire:1"> 
23 ······<ocil:title>Enable·randomization·of·the·page·allocator</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-grub2_page_alloc_shuffle_argument_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
29 ······<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title>29 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_srv_nosuid_ocil:questionnaire:1">
35 ······<ocil:title>Disable·TIPC·Support</ocil:title>35 ······<ocil:title>Add·nosuid·Option·to·/srv</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-mount_option_srv_nosuid_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
41 ······<ocil:title>Uninstall·talk·Package</ocil:title>41 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_group_root_owned_ocil:questionnaire:1">
47 ······<ocil:title>Uninstall·setroubleshoot-server·Package</ocil:title>47 ······<ocil:title>Verify·that·system·commands·directories·have·root·as·a·group·owner</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_group_root_owned_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_checking_systemd_timer_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>53 ······<ocil:title>Configure·Systemd·Timer·Execution·of·AIDE</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_checking_systemd_timer_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">
59 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>59 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
65 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>65 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1">
71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>71 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_sudoersd_ocil:questionnaire:1"> 
77 ······<ocil:title>Verify·Group·Who·Owns·/etc/sudoers.d·Directory</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
 77 ······<ocil:title>Kernel·panic·oops</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
83 ······<ocil:title>Avoid·speculative·indirect·branches·in·kernel</ocil:title>83 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_retpoline_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_vsyscall_xonly_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_sched_stack_end_check_ocil:questionnaire:1">
89 ······<ocil:title>Disable·vsyscall·emulate·execution·only</ocil:title>89 ······<ocil:title>Detect·stack·corruption·on·calls·to·schedule()</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_vsyscall_xonly_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_sched_stack_end_check_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
95 ······<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>95 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1">
 101 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
107 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>107 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1">
113 ······<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>113 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_chrony_keys_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·Group·Who·Owns·/etc/chrony.keys·File</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
 119 ······<ocil:title>Disable·RDS·Support</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_kmod_ocil:questionnaire:1"> 
Max diff block lines reached; 1179567/1192408 bytes (98.92%) of diff not shown.
2.51 KB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
2.41 KB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
Ordering differences only
    
Offset 239, 23 lines modifiedOffset 239, 23 lines modified
239 ······</cpe-lang:logical-test>239 ······</cpe-lang:logical-test>
240 ····</cpe-lang:platform>240 ····</cpe-lang:platform>
241 ····<cpe-lang:platform·id="package_bash">241 ····<cpe-lang:platform·id="package_bash">
242 ······<cpe-lang:logical-test·operator="AND"·negate="false">242 ······<cpe-lang:logical-test·operator="AND"·negate="false">
243 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>243 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
244 ······</cpe-lang:logical-test>244 ······</cpe-lang:logical-test>
245 ····</cpe-lang:platform>245 ····</cpe-lang:platform>
246 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">246 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
247 ······<cpe-lang:logical-test·operator="AND"·negate="false">247 ······<cpe-lang:logical-test·operator="AND"·negate="false">
248 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>248 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
249 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
250 ······</cpe-lang:logical-test>249 ······</cpe-lang:logical-test>
251 ····</cpe-lang:platform>250 ····</cpe-lang:platform>
252 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">251 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
253 ······<cpe-lang:logical-test·operator="AND"·negate="false">252 ······<cpe-lang:logical-test·operator="AND"·negate="false">
254 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>253 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 254 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
255 ······</cpe-lang:logical-test>255 ······</cpe-lang:logical-test>
256 ····</cpe-lang:platform>256 ····</cpe-lang:platform>
257 ····<cpe-lang:platform·id="package_shadow-utils">257 ····<cpe-lang:platform·id="package_shadow-utils">
258 ······<cpe-lang:logical-test·operator="AND"·negate="false">258 ······<cpe-lang:logical-test·operator="AND"·negate="false">
259 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>259 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
260 ······</cpe-lang:logical-test>260 ······</cpe-lang:logical-test>
261 ····</cpe-lang:platform>261 ····</cpe-lang:platform>
79.5 MB
ssg-nondebian_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0····18172·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0····18176·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0·37084288·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0·37081288·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
79.5 MB
data.tar.xz
79.5 MB
data.tar
3.5 KB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs-stig_gui.html
    
Offset 8560, 18 lines modifiedOffset 8560, 18 lines modified
000216f0:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in000216f0:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in
00021700:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot00021700:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot
00021710:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom00021710:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom
00021720:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit00021720:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit
00021730:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system·00021730:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system·
00021740:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s)..00021740:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s)..
00021750:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va00021750:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va
00021760:·725f·736e·6d70·645f·726f·5f73·7472·696e··r_snmpd_ro_strin00021760:·725f·736e·6d70·645f·7277·5f73·7472·696e··r_snmpd_rw_strin
00021770:·673d·6368·616e·6765·6d65·726f·3c62·722f··g=changemero<br/00021770:·673d·6368·616e·6765·6d65·7277·3c62·722f··g=changemerw<br/
00021780:·3e76·6172·5f73·6e6d·7064·5f72·775f·7374··>var_snmpd_rw_st00021780:·3e76·6172·5f73·6e6d·7064·5f72·6f5f·7374··>var_snmpd_ro_st
00021790:·7269·6e67·3d63·6861·6e67·656d·6572·773c··ring=changemerw<00021790:·7269·6e67·3d63·6861·6e67·656d·6572·6f3c··ring=changemero<
000217a0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>.000217a0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>.
000217b0:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>.000217b0:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>.
000217c0:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.·000217c0:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.·
000217d0:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K000217d0:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K
000217e0:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li000217e0:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li
000217f0:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D000217f0:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D
00021800:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack00021800:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack
1.87 KB
html2text {}
    
Offset 2919, 16 lines modifiedOffset 2919, 16 lines modified
2919 ··············································································network·management2919 ··············································································network·management
2920 ··············································································protocol·(SNMP)2920 ··············································································protocol·(SNMP)
2921 ··············································································community·strings2921 ··············································································community·strings
2922 ··············································································must·be·changed·to2922 ··············································································must·be·changed·to
2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.2923 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.
2924 ··································the·default·community·strings·of·public·and·If·the·service·is2924 ··································the·default·community·strings·of·public·and·If·the·service·is
2925 ··································private.·This·profile·configures·new·read-··running·with·the2925 ··································private.·This·profile·configures·new·read-··running·with·the
2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_ro_string=changemero2926 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_rw_string=changemerw
2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_rw_string=changemerw2927 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_ro_string=changemero
2928 ··································Once·the·default·community·strings·have·····then·anyone·can2928 ··································Once·the·default·community·strings·have·····then·anyone·can
2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about2929 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about
2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the2930 ··································$·sudo·systemctl·restart·snmpd··············the·system·and·the
2931 ··············································································network·and·use·the2931 ··············································································network·and·use·the
2932 ··············································································information·to2932 ··············································································information·to
2933 ··············································································potentially2933 ··············································································potentially
2934 ··············································································compromise·the2934 ··············································································compromise·the
3.25 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-ospp.html
    
Offset 4070, 15 lines modifiedOffset 4070, 15 lines modified
4070 <tt>RekeyLimit</tt>.4070 <tt>RekeyLimit</tt>.
4071 ··</td>4071 ··</td>
4072 ··<td·xml:lang="en-US">4072 ··<td·xml:lang="en-US">
4073 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4073 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4074 time-based·limit,·effects·of·potential·attacks·against4074 time-based·limit,·effects·of·potential·attacks·against
4075 encryption·keys·are·limited.4075 encryption·keys·are·limited.
4076 ··</td>4076 ··</td>
4077 ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td>4077 ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td>
4078 </tr>4078 </tr>
4079 <tr>4079 <tr>
4080 ··<td></td>4080 ··<td></td>
4081 ··<td>N/A</td>4081 ··<td>N/A</td>
4082 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>4082 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>
4083 ··<td·xml:lang="en-US">4083 ··<td·xml:lang="en-US">
4084 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure4084 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure
2.52 KB
html2text {}
    
Offset 3341, 16 lines modifiedOffset 3341, 16 lines modified
3341 ··················································································································options,·which·can3341 ··················································································································options,·which·can
3342 ··················································································································help·protect3342 ··················································································································help·protect
3343 ··················································································································programs·which·use3343 ··················································································································programs·which·use
3344 ··················································································································it.3344 ··················································································································it.
3345 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the3345 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the
3346 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the3346 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the
3347 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and3347 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and
3348 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour3348 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G
3349 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G3349 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour
3350 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks3350 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks
3351 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption3351 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption
3352 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.3352 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.
3353 ··················································································································Some·SSH3353 ··················································································································Some·SSH
3354 ··················································································································implementations·use3354 ··················································································································implementations·use
3355 ··················································································································the·openssl·library3355 ··················································································································the·openssl·library
3356 ··················································································································for·entropy,·which3356 ··················································································································for·entropy,·which
3.49 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-stig.html
    
Offset 24427, 17 lines modifiedOffset 24427, 17 lines modified
0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li
0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·
0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack
0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp
0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li
0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·
0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l
 0005f710:·696d·6974·5f73·697a·653d·3147·3c62·722f··imit_size=1G<br/
 0005f720:·3e76·6172·5f72·656b·6579·5f6c·696d·6974··>var_rekey_limit
0005f710:·696d·6974·5f74·696d·653d·3168·6f75·723c··imit_time=1hour<0005f730:·5f74·696d·653d·3168·6f75·723c·2f74·643e··_time=1hour</td>
0005f720:·6272·2f3e·7661·725f·7265·6b65·795f·6c69··br/>var_rekey_li 
0005f730:·6d69·745f·7369·7a65·3d31·473c·2f74·643e··mit_size=1G</td> 
0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t
0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/
0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH
0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str
0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s
0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x
0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
2.0 KB
html2text {}
    
Offset 7774, 16 lines modifiedOffset 7774, 16 lines modified
7774 ·································private·key.··········································system·where·the7774 ·································private·key.··········································system·where·the
7775 ·······················································································associated·public7775 ·······················································································associated·public
7776 ·······················································································key·has·been7776 ·······················································································key·has·been
7777 ·······················································································installed.7777 ·······················································································installed.
7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G
7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour
7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7784 ·································RekeyLimit·1G·1hour···································against·encryption7784 ·································RekeyLimit·1G·1hour···································against·encryption
7785 ·······················································································keys·are·limited.7785 ·······················································································keys·are·limited.
7786 ·······················································································SSH·implementation7786 ·······················································································SSH·implementation
7787 ·······················································································in·Oracle·Linux·87787 ·······················································································in·Oracle·Linux·8
7788 ·······················································································uses·the·openssl7788 ·······················································································uses·the·openssl
7789 ·······················································································library,·which7789 ·······················································································library,·which
6.48 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-ospp.html
    
Offset 4075, 15 lines modifiedOffset 4075, 15 lines modified
4075 <tt>RekeyLimit</tt>.4075 <tt>RekeyLimit</tt>.
4076 ··</td>4076 ··</td>
4077 ··<td·xml:lang="en-US">4077 ··<td·xml:lang="en-US">
4078 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4078 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4079 time-based·limit,·effects·of·potential·attacks·against4079 time-based·limit,·effects·of·potential·attacks·against
4080 encryption·keys·are·limited.4080 encryption·keys·are·limited.
4081 ··</td>4081 ··</td>
4082 ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td>4082 ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td>
4083 </tr>4083 </tr>
4084 <tr>4084 <tr>
4085 ··<td></td>4085 ··<td></td>
4086 ··<td>CCE-83349-1</td>4086 ··<td>CCE-83349-1</td>
4087 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>4087 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>
4088 ··<td·xml:lang="en-US">4088 ··<td·xml:lang="en-US">
4089 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure4089 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure
Offset 4138, 15 lines modifiedOffset 4138, 15 lines modified
4138 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4138 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4139 ··</td>4139 ··</td>
4140 ··<td·xml:lang="en-US">4140 ··<td·xml:lang="en-US">
4141 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4141 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4142 time-based·limit,·effects·of·potential·attacks·against4142 time-based·limit,·effects·of·potential·attacks·against
4143 encryption·keys·are·limited.4143 encryption·keys·are·limited.
4144 ··</td>4144 ··</td>
4145 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>4145 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>
4146 </tr>4146 </tr>
4147 <tr>4147 <tr>
4148 ··<td></td>4148 ··<td></td>
4149 ··<td>CCE-82462-3</td>4149 ··<td>CCE-82462-3</td>
4150 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4150 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4151 ··<td·xml:lang="en-US">4151 ··<td·xml:lang="en-US">
4152 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4152 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
5.11 KB
html2text {}
    
Offset 3356, 16 lines modifiedOffset 3356, 16 lines modified
3356 ······················································································································options,·which·can3356 ······················································································································options,·which·can
3357 ······················································································································help·protect3357 ······················································································································help·protect
3358 ······················································································································programs·which·use3358 ······················································································································programs·which·use
3359 ······················································································································it.3359 ······················································································································it.
3360 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the3360 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the
3361 ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the3361 ·····························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the
3362 ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and3362 ·····CCE-···Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and
3363 ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour3363 ·····82880-·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G
3364 ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G3364 ·····6······renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour
3365 ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks3365 ············for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks
3366 ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption3366 ·····························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption
3367 ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited.3367 ·····························containing·definition·of·RekeyLimit.·····················································keys·are·limited.
3368 ······················································································································Some·SSH3368 ······················································································································Some·SSH
3369 ······················································································································implementations·use3369 ······················································································································implementations·use
3370 ······················································································································the·openssl·library3370 ······················································································································the·openssl·library
3371 ······················································································································for·entropy,·which3371 ······················································································································for·entropy,·which
Offset 3416, 16 lines modifiedOffset 3416, 16 lines modified
3416 ······················································································································generator·used·by3416 ······················································································································generator·used·by
3417 ······················································································································SSH·would·be·known3417 ······················································································································SSH·would·be·known
3418 ······················································································································to·potential3418 ······················································································································to·potential
3419 ······················································································································attackers.3419 ······················································································································attackers.
3420 ······················································································································By·decreasing·the3420 ······················································································································By·decreasing·the
3421 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3421 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3422 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3422 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3423 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour3423 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G
3424 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G3424 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour
3425 ·····························RekeyLimit·1G·1hour······································································potential·attacks3425 ·····························RekeyLimit·1G·1hour······································································potential·attacks
3426 ······················································································································against·encryption3426 ······················································································································against·encryption
3427 ······················································································································keys·are·limited.3427 ······················································································································keys·are·limited.
3428 ······················································································································SSH·implementation3428 ······················································································································SSH·implementation
3429 ······················································································································in·Red·Hat3429 ······················································································································in·Red·Hat
3430 ······················································································································Enterprise·Linux·83430 ······················································································································Enterprise·Linux·8
3431 ······················································································································uses·the·openssl3431 ······················································································································uses·the·openssl
1.31 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
1.18 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>
8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>
9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>
10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
756 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
756 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 98811, 15 lines modifiedOffset 98811, 15 lines modified
98811 ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>98811 ··············<xccdf-1.2:check-content-ref·href="ssg-al2023-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>
98812 ············</xccdf-1.2:check>98812 ············</xccdf-1.2:check>
98813 ··········</xccdf-1.2:Rule>98813 ··········</xccdf-1.2:Rule>
98814 ········</xccdf-1.2:Group>98814 ········</xccdf-1.2:Group>
98815 ······</xccdf-1.2:Group>98815 ······</xccdf-1.2:Group>
98816 ····</xccdf-1.2:Benchmark>98816 ····</xccdf-1.2:Benchmark>
98817 ··</ds:component>98817 ··</ds:component>
98818 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-02-28T20:08:00">98818 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-oval.xml"·timestamp="2025-03-01T22:08:00">
98819 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">98819 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
98820 ······<oval-def:generator>98820 ······<oval-def:generator>
98821 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>98821 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
98822 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>98822 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
98823 ········<oval:schema_version>5.11</oval:schema_version>98823 ········<oval:schema_version>5.11</oval:schema_version>
98824 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>98824 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
98825 ······</oval-def:generator>98825 ······</oval-def:generator>
Offset 117150, 3104 lines modifiedOffset 117150, 3104 lines modified
117150 ············</oval-def:arithmetic>117150 ············</oval-def:arithmetic>
117151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>117151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
117152 ··········</oval-def:arithmetic>117152 ··········</oval-def:arithmetic>
117153 ········</oval-def:local_variable>117153 ········</oval-def:local_variable>
117154 ······</oval-def:variables>117154 ······</oval-def:variables>
117155 ····</oval-def:oval_definitions>117155 ····</oval-def:oval_definitions>
117156 ··</ds:component>117156 ··</ds:component>
117157 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-02-28T20:08:00">117157 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-ocil.xml"·timestamp="2025-03-01T22:08:00">
117158 ····<ocil:ocil>117158 ····<ocil:ocil>
117159 ······<ocil:generator>117159 ······<ocil:generator>
117160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>117160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
117161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>117161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
117162 ········<ocil:schema_version>2.0</ocil:schema_version>117162 ········<ocil:schema_version>2.0</ocil:schema_version>
117163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>117163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
117164 ······</ocil:generator>117164 ······</ocil:generator>
117165 ······<ocil:questionnaires>117165 ······<ocil:questionnaires>
117166 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">117166 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
117167 ··········<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>117167 ··········<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
117168 ··········<ocil:actions>117168 ··········<ocil:actions>
117169 ············<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>117169 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
117170 ··········</ocil:actions>117170 ··········</ocil:actions>
117171 ········</ocil:questionnaire>117171 ········</ocil:questionnaire>
117172 ········<ocil:questionnaire·id="ocil:ssg-package_avahi_removed_ocil:questionnaire:1"> 
117173 ··········<ocil:title>Uninstall·avahi·Server·Package</ocil:title>117172 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">
 117173 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>
117174 ··········<ocil:actions>117174 ··········<ocil:actions>
117175 ············<ocil:test_action_ref>ocil:ssg-package_avahi_removed_action:testaction:1</ocil:test_action_ref>117175 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
117176 ··········</ocil:actions>117176 ··········</ocil:actions>
117177 ········</ocil:questionnaire>117177 ········</ocil:questionnaire>
117178 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1"> 
117179 ··········<ocil:title>Verify·Group·Who·Owns·Backup·passwd·File</ocil:title>117178 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
 117179 ··········<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>
117180 ··········<ocil:actions>117180 ··········<ocil:actions>
117181 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>117181 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
117182 ··········</ocil:actions>117182 ··········</ocil:actions>
117183 ········</ocil:questionnaire>117183 ········</ocil:questionnaire>
117184 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_net_ocil:questionnaire:1">117184 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">
117185 ··········<ocil:title>Verify·ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>117185 ··········<ocil:title>Add·nosuid·Option·to·/home</ocil:title>
117186 ··········<ocil:actions>117186 ··········<ocil:actions>
117187 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_net_action:testaction:1</ocil:test_action_ref>117187 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>
117188 ··········</ocil:actions>117188 ··········</ocil:actions>
117189 ········</ocil:questionnaire>117189 ········</ocil:questionnaire>
117190 ········<ocil:questionnaire·id="ocil:ssg-package_ftp_removed_ocil:questionnaire:1">117190 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">
117191 ··········<ocil:title>Remove·ftp·Package</ocil:title>117191 ··········<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>
117192 ··········<ocil:actions>117192 ··········<ocil:actions>
117193 ············<ocil:test_action_ref>ocil:ssg-package_ftp_removed_action:testaction:1</ocil:test_action_ref>117193 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>
117194 ··········</ocil:actions>117194 ··········</ocil:actions>
117195 ········</ocil:questionnaire>117195 ········</ocil:questionnaire>
117196 ········<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">117196 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">
117197 ··········<ocil:title>Enable·auditd·Service</ocil:title>117197 ··········<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>
117198 ··········<ocil:actions>117198 ··········<ocil:actions>
117199 ············<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>117199 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>
117200 ··········</ocil:actions>117200 ··········</ocil:actions>
117201 ········</ocil:questionnaire>117201 ········</ocil:questionnaire>
117202 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">117202 ········<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
117203 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>117203 ··········<ocil:title>Verify·Owner·on·crontab</ocil:title>
117204 ··········<ocil:actions>117204 ··········<ocil:actions>
117205 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>117205 ············<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>
117206 ··········</ocil:actions>117206 ··········</ocil:actions>
117207 ········</ocil:questionnaire>117207 ········</ocil:questionnaire>
117208 ········<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">117208 ········<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">
117209 ··········<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>117209 ··········<ocil:title>Verify·/boot/grub2/grub.cfg·User·Ownership</ocil:title>
117210 ··········<ocil:actions>117210 ··········<ocil:actions>
117211 ············<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>117211 ············<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
117212 ··········</ocil:actions>117212 ··········</ocil:actions>
117213 ········</ocil:questionnaire>117213 ········</ocil:questionnaire>
117214 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_create_ocil:questionnaire:1"> 
117215 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·create_module</ocil:title>117214 ········<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">
 117215 ··········<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>
117216 ··········<ocil:actions>117216 ··········<ocil:actions>
117217 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_create_action:testaction:1</ocil:test_action_ref>117217 ············<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>
117218 ··········</ocil:actions>117218 ··········</ocil:actions>
117219 ········</ocil:questionnaire>117219 ········</ocil:questionnaire>
117220 ········<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">117220 ········<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
117221 ··········<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>117221 ··········<ocil:title>Uninstall·vsftpd·Package</ocil:title>
117222 ··········<ocil:actions>117222 ··········<ocil:actions>
117223 ············<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>117223 ············<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
117224 ··········</ocil:actions>117224 ··········</ocil:actions>
117225 ········</ocil:questionnaire>117225 ········</ocil:questionnaire>
117226 ········<ocil:questionnaire·id="ocil:ssg-ensure_root_password_configured_ocil:questionnaire:1">117226 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
117227 ··········<ocil:title>Ensure·Authentication·Required·for·Single·User·Mode</ocil:title>117227 ··········<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
117228 ··········<ocil:actions>117228 ··········<ocil:actions>
117229 ············<ocil:test_action_ref>ocil:ssg-ensure_root_password_configured_action:testaction:1</ocil:test_action_ref>117229 ············<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
117230 ··········</ocil:actions>117230 ··········</ocil:actions>
117231 ········</ocil:questionnaire>117231 ········</ocil:questionnaire>
117232 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"> 
117233 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>117232 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1">
Max diff block lines reached; 762035/773977 bytes (98.46%) of diff not shown.
720 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
720 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
Ordering differences only
    
Offset 3, 3095 lines modifiedOffset 3, 3095 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
11 ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>11 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_avahi_removed_ocil:questionnaire:1"> 
17 ······<ocil:title>Uninstall·avahi·Server·Package</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_avahi_removed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Group·Who·Owns·Backup·passwd·File</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
 23 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_net_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">
29 ······<ocil:title>Verify·ownership·of·System·Login·Banner·for·Remote·Connections</ocil:title>29 ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_net_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_ftp_removed_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">
35 ······<ocil:title>Remove·ftp·Package</ocil:title>35 ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_ftp_removed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">
41 ······<ocil:title>Enable·auditd·Service</ocil:title>41 ······<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>47 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>53 ······<ocil:title>Verify·/boot/grub2/grub.cfg·User·Ownership</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_create_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·create_module</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">
 59 ······<ocil:title>Verify·Only·Root·Has·UID·0</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_create_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>65 ······<ocil:title>Uninstall·vsftpd·Package</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-ensure_root_password_configured_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·Authentication·Required·for·Single·User·Mode</ocil:title>71 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-ensure_root_password_configured_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchownat</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1">
 77 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>83 ······<ocil:title>Disable·SCTP·Support</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-no_password_auth_for_systemaccounts_ocil:questionnaire:1"> 
89 ······<ocil:title>Ensure·that·System·Accounts·Are·Locked</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-package_nftables_installed_ocil:questionnaire:1">
 89 ······<ocil:title>Install·nftables·Package</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-no_password_auth_for_systemaccounts_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-package_nftables_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_user_cfg_ocil:questionnaire:1">
95 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title>95 ······<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_user_cfg_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
101 ······<ocil:title>Add·noexec·Option·to·/var/tmp</ocil:title>101 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>107 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-firewalld_loopback_traffic_restricted_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">
113 ······<ocil:title>Configure·Firewalld·to·Restrict·Loopback·Traffic</ocil:title>113 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-firewalld_loopback_traffic_restricted_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
119 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>119 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">
Max diff block lines reached; 724409/736898 bytes (98.31%) of diff not shown.
901 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
901 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 58534, 15 lines modifiedOffset 58534, 15 lines modified
58534 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>58534 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux2-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
58535 ············</xccdf-1.2:check>58535 ············</xccdf-1.2:check>
58536 ··········</xccdf-1.2:Rule>58536 ··········</xccdf-1.2:Rule>
58537 ········</xccdf-1.2:Group>58537 ········</xccdf-1.2:Group>
58538 ······</xccdf-1.2:Group>58538 ······</xccdf-1.2:Group>
58539 ····</xccdf-1.2:Benchmark>58539 ····</xccdf-1.2:Benchmark>
58540 ··</ds:component>58540 ··</ds:component>
58541 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-02-28T20:08:00">58541 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-oval.xml"·timestamp="2025-03-01T22:08:00">
58542 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">58542 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
58543 ······<oval-def:generator>58543 ······<oval-def:generator>
58544 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>58544 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
58545 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>58545 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
58546 ········<oval:schema_version>5.11</oval:schema_version>58546 ········<oval:schema_version>5.11</oval:schema_version>
58547 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>58547 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
58548 ······</oval-def:generator>58548 ······</oval-def:generator>
Offset 79715, 5376 lines modifiedOffset 79715, 5376 lines modified
79715 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>79715 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
79716 ··········</oval-def:regex_capture>79716 ··········</oval-def:regex_capture>
79717 ········</oval-def:local_variable>79717 ········</oval-def:local_variable>
79718 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>79718 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>
79719 ······</oval-def:variables>79719 ······</oval-def:variables>
79720 ····</oval-def:oval_definitions>79720 ····</oval-def:oval_definitions>
79721 ··</ds:component>79721 ··</ds:component>
79722 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-02-28T20:08:00">79722 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-ocil.xml"·timestamp="2025-03-01T22:08:00">
79723 ····<ocil:ocil>79723 ····<ocil:ocil>
79724 ······<ocil:generator>79724 ······<ocil:generator>
79725 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>79725 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
79726 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>79726 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
79727 ········<ocil:schema_version>2.0</ocil:schema_version>79727 ········<ocil:schema_version>2.0</ocil:schema_version>
79728 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>79728 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
79729 ······</ocil:generator>79729 ······</ocil:generator>
79730 ······<ocil:questionnaires>79730 ······<ocil:questionnaires>
79731 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1"> 
79732 ··········<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title> 
79733 ··········<ocil:actions> 
79734 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref> 
79735 ··········</ocil:actions> 
79736 ········</ocil:questionnaire> 
79737 ········<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">79731 ········<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
79738 ··········<ocil:title>Uninstall·talk·Package</ocil:title>79732 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
79739 ··········<ocil:actions>79733 ··········<ocil:actions>
79740 ············<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>79734 ············<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
79741 ··········</ocil:actions>79735 ··········</ocil:actions>
79742 ········</ocil:questionnaire>79736 ········</ocil:questionnaire>
79743 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">79737 ········<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">
79744 ··········<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>79738 ··········<ocil:title>The·Chronyd·service·is·enabled</ocil:title>
79745 ··········<ocil:actions>79739 ··········<ocil:actions>
79746 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>79740 ············<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>
79747 ··········</ocil:actions>79741 ··········</ocil:actions>
79748 ········</ocil:questionnaire>79742 ········</ocil:questionnaire>
79749 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">79743 ········<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">
79750 ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title>79744 ··········<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>
79751 ··········<ocil:actions>79745 ··········<ocil:actions>
79752 ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>79746 ············<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>
79753 ··········</ocil:actions>79747 ··········</ocil:actions>
79754 ········</ocil:questionnaire>79748 ········</ocil:questionnaire>
79755 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1"> 
79756 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>79749 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1">
 79750 ··········<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
79757 ··········<ocil:actions>79751 ··········<ocil:actions>
79758 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>79752 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>
79759 ··········</ocil:actions>79753 ··········</ocil:actions>
79760 ········</ocil:questionnaire>79754 ········</ocil:questionnaire>
79761 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">79755 ········<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">
79762 ··········<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>79756 ··········<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>
79763 ··········<ocil:actions>79757 ··········<ocil:actions>
79764 ············<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>79758 ············<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>
79765 ··········</ocil:actions>79759 ··········</ocil:actions>
79766 ········</ocil:questionnaire>79760 ········</ocil:questionnaire>
79767 ········<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">79761 ········<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">
79768 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>79762 ··········<ocil:title>Enable·syslog-ng·Service</ocil:title>
79769 ··········<ocil:actions>79763 ··········<ocil:actions>
79770 ············<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>79764 ············<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>
79771 ··········</ocil:actions>79765 ··········</ocil:actions>
79772 ········</ocil:questionnaire>79766 ········</ocil:questionnaire>
79773 ········<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">79767 ········<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
79774 ··········<ocil:title>Verify·firewalld·Enabled</ocil:title>79768 ··········<ocil:title>IOMMU·configuration·directive</ocil:title>
79775 ··········<ocil:actions>79769 ··········<ocil:actions>
79776 ············<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>79770 ············<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
79777 ··········</ocil:actions>79771 ··········</ocil:actions>
79778 ········</ocil:questionnaire>79772 ········</ocil:questionnaire>
79779 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">79773 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">
79780 ··········<ocil:title>Enable·GSSAPI·Authentication</ocil:title>79774 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>
79781 ··········<ocil:actions>79775 ··········<ocil:actions>
79782 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>79776 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>
79783 ··········</ocil:actions>79777 ··········</ocil:actions>
79784 ········</ocil:questionnaire>79778 ········</ocil:questionnaire>
79785 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">79779 ········<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">
79786 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>79780 ··········<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>
79787 ··········<ocil:actions>79781 ··········<ocil:actions>
79788 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>79782 ············<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>
79789 ··········</ocil:actions>79783 ··········</ocil:actions>
79790 ········</ocil:questionnaire>79784 ········</ocil:questionnaire>
79791 ········<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">79785 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
79792 ··········<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>79786 ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
79793 ··········<ocil:actions>79787 ··········<ocil:actions>
79794 ············<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>79788 ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
79795 ··········</ocil:actions>79789 ··········</ocil:actions>
79796 ········</ocil:questionnaire>79790 ········</ocil:questionnaire>
79797 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">79791 ········<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">
79798 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>79792 ··········<ocil:title>Uninstall·bind·Package</ocil:title>
79799 ··········<ocil:actions>79793 ··········<ocil:actions>
79800 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>79794 ············<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 910321/922312 bytes (98.70%) of diff not shown.
859 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
859 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
Ordering differences only
    
Offset 3, 5367 lines modifiedOffset 3, 5367 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
17 ······<ocil:title>Uninstall·talk·Package</ocil:title>11 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>17 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>23 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·NOPASSWD</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1"> 
35 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1">
 29 ······<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">
41 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>35 ······<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">
 41 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
53 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>47 ······<ocil:title>IOMMU·configuration·directive</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">
59 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>53 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>59 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>65 ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">
77 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>71 ······<ocil:title>Uninstall·bind·Package</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1"> 
83 ······<ocil:title>Limit·Password·Reuse:·system-auth</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
 77 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>83 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_at_allow_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·/etc/at.allow·file</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_at_allow_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·/srv·Located·On·Separate·Partition</ocil:title>95 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1"> 
107 ······<ocil:title>IOMMU·configuration·directive</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">
113 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>107 ······<ocil:title>Randomize·the·address·of·the·kernel·image·(KASLR)</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_base_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
 113 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">
Max diff block lines reached; 867096/879309 bytes (98.61%) of diff not shown.
893 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
893 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 57666, 15 lines modifiedOffset 57666, 15 lines modified
57666 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>57666 ··············<xccdf-1.2:check-content-ref·href="ssg-alinux3-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
57667 ············</xccdf-1.2:check>57667 ············</xccdf-1.2:check>
57668 ··········</xccdf-1.2:Rule>57668 ··········</xccdf-1.2:Rule>
57669 ········</xccdf-1.2:Group>57669 ········</xccdf-1.2:Group>
57670 ······</xccdf-1.2:Group>57670 ······</xccdf-1.2:Group>
57671 ····</xccdf-1.2:Benchmark>57671 ····</xccdf-1.2:Benchmark>
57672 ··</ds:component>57672 ··</ds:component>
57673 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-02-28T20:08:00">57673 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-oval.xml"·timestamp="2025-03-01T22:08:00">
57674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">57674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
57675 ······<oval-def:generator>57675 ······<oval-def:generator>
57676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>57676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
57677 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>57677 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
57678 ········<oval:schema_version>5.11</oval:schema_version>57678 ········<oval:schema_version>5.11</oval:schema_version>
57679 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>57679 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
57680 ······</oval-def:generator>57680 ······</oval-def:generator>
Offset 77997, 2980 lines modifiedOffset 77997, 2980 lines modified
77997 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>77997 ············<oval-def:object_component·item_field="subexpression"·object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
77998 ··········</oval-def:regex_capture>77998 ··········</oval-def:regex_capture>
77999 ········</oval-def:local_variable>77999 ········</oval-def:local_variable>
78000 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>78000 ········<oval-def:external_variable·id="oval:ssg-sshd_required:var:1"·version="1"·datatype="int"·comment="May·be·defined·by·Profiles·to·explicitly·say·if·sshd·is·required·or·not"/>
78001 ······</oval-def:variables>78001 ······</oval-def:variables>
78002 ····</oval-def:oval_definitions>78002 ····</oval-def:oval_definitions>
78003 ··</ds:component>78003 ··</ds:component>
78004 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-02-28T20:08:00">78004 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-ocil.xml"·timestamp="2025-03-01T22:08:00">
78005 ····<ocil:ocil>78005 ····<ocil:ocil>
78006 ······<ocil:generator>78006 ······<ocil:generator>
78007 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>78007 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
78008 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>78008 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
78009 ········<ocil:schema_version>2.0</ocil:schema_version>78009 ········<ocil:schema_version>2.0</ocil:schema_version>
78010 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>78010 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
78011 ······</ocil:generator>78011 ······</ocil:generator>
78012 ······<ocil:questionnaires>78012 ······<ocil:questionnaires>
78013 ········<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">78013 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
 78014 ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
78014 ··········<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title> 
78015 ··········<ocil:actions> 
78016 ············<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref> 
78017 ··········</ocil:actions> 
78018 ········</ocil:questionnaire> 
78019 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1"> 
78020 ··········<ocil:title>Ensure·All·SGID·Executables·Are·Authorized</ocil:title> 
78021 ··········<ocil:actions>78015 ··········<ocil:actions>
78022 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>78016 ············<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
78023 ··········</ocil:actions>78017 ··········</ocil:actions>
78024 ········</ocil:questionnaire>78018 ········</ocil:questionnaire>
78025 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">78019 ········<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
78026 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>78020 ··········<ocil:title>Remove·NIS·Client</ocil:title>
78027 ··········<ocil:actions>78021 ··········<ocil:actions>
78028 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>78022 ············<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
78029 ··········</ocil:actions>78023 ··········</ocil:actions>
78030 ········</ocil:questionnaire>78024 ········</ocil:questionnaire>
78031 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">78025 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
78032 ··········<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>78026 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
78033 ··········<ocil:actions>78027 ··········<ocil:actions>
78034 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>78028 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
78035 ··········</ocil:actions>78029 ··········</ocil:actions>
78036 ········</ocil:questionnaire>78030 ········</ocil:questionnaire>
78037 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1">78031 ········<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
78038 ··········<ocil:title>Ensure·All·SUID·Executables·Are·Authorized</ocil:title>78032 ··········<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>
78039 ··········<ocil:actions>78033 ··········<ocil:actions>
78040 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>78034 ············<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
78041 ··········</ocil:actions>78035 ··········</ocil:actions>
78042 ········</ocil:questionnaire>78036 ········</ocil:questionnaire>
78043 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">78037 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">
78044 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>78038 ··········<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>
78045 ··········<ocil:actions>78039 ··········<ocil:actions>
78046 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>78040 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>
78047 ··········</ocil:actions>78041 ··········</ocil:actions>
78048 ········</ocil:questionnaire>78042 ········</ocil:questionnaire>
78049 ········<ocil:questionnaire·id="ocil:ssg-service_oddjobd_disabled_ocil:questionnaire:1">78043 ········<ocil:questionnaire·id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">
78050 ··········<ocil:title>Disable·Odd·Job·Daemon·(oddjobd)</ocil:title>78044 ··········<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·requiretty</ocil:title>
78051 ··········<ocil:actions>78045 ··········<ocil:actions>
78052 ············<ocil:test_action_ref>ocil:ssg-service_oddjobd_disabled_action:testaction:1</ocil:test_action_ref>78046 ············<ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>
78053 ··········</ocil:actions>78047 ··········</ocil:actions>
78054 ········</ocil:questionnaire>78048 ········</ocil:questionnaire>
78055 ········<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"> 
78056 ··········<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>78049 ········<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
 78050 ··········<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
78057 ··········<ocil:actions>78051 ··········<ocil:actions>
78058 ············<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>78052 ············<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
78059 ··········</ocil:actions>78053 ··········</ocil:actions>
78060 ········</ocil:questionnaire>78054 ········</ocil:questionnaire>
78061 ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">78055 ········<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">
78062 ··········<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>78056 ··········<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>
78063 ··········<ocil:actions>78057 ··········<ocil:actions>
78064 ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>78058 ············<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>
78065 ··········</ocil:actions>78059 ··········</ocil:actions>
78066 ········</ocil:questionnaire>78060 ········</ocil:questionnaire>
78067 ········<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">78061 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1">
78068 ··········<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>78062 ··········<ocil:title>Set·Password·Minimum·Length·in·login.defs</ocil:title>
78069 ··········<ocil:actions>78063 ··········<ocil:actions>
78070 ············<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>78064 ············<ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref>
78071 ··········</ocil:actions>78065 ··········</ocil:actions>
78072 ········</ocil:questionnaire>78066 ········</ocil:questionnaire>
78073 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1"> 
78074 ··········<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>78067 ········<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
 78068 ··········<ocil:title>Account·Lockouts·Must·Persist</ocil:title>
78075 ··········<ocil:actions>78069 ··········<ocil:actions>
78076 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>78070 ············<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
78077 ··········</ocil:actions>78071 ··········</ocil:actions>
78078 ········</ocil:questionnaire>78072 ········</ocil:questionnaire>
78079 ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1"> 
78080 ··········<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>78073 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">
Max diff block lines reached; 902362/914456 bytes (98.68%) of diff not shown.
852 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
852 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
Ordering differences only
    
Offset 3, 2971 lines modifiedOffset 3, 2971 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
11 ······<ocil:title>Ensure·that·chronyd·is·running·under·chrony·user·account</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·All·SGID·Executables·Are·Authorized</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
23 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>17 ······<ocil:title>Remove·NIS·Client</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
29 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>23 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·All·SUID·Executables·Are·Authorized</ocil:title>29 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">
41 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>35 ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_oddjobd_disabled_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Odd·Job·Daemon·(oddjobd)</ocil:title>41 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·requiretty</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_oddjobd_disabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"> 
53 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">
59 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>53 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>59 ······<ocil:title>Set·Password·Minimum·Length·in·login.defs</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1"> 
71 ······<ocil:title>Record·attempts·to·alter·time·through·adjtimex</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
 65 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1"> 
77 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>77 ······<ocil:title>Ensure·All·SGID·Executables·Are·Authorized</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
89 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>83 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_daily_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Group·Who·Owns·cron.daily</ocil:title>89 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_daily_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_telnet_removed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1">
101 ······<ocil:title>Remove·telnet·Clients</ocil:title>95 ······<ocil:title>Disable·Apache·Qpid·(qpidd)</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_telnet_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-service_qpidd_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1">
107 ······<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>101 ······<ocil:title>Verify·ufw·Enabled</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_ufw_enabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">
113 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>107 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
119 ······<ocil:title>Verify·Owner·on·cron.daily</ocil:title>113 ······<ocil:title>Disable·the·Automounter</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">
125 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>119 ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>
Max diff block lines reached; 859678/872013 bytes (98.59%) of diff not shown.
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-almalinux9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-almalinux9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_oval-org.almalinux.alsa-9.xml.bz2"·xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:almalinux:almalinux:9">
31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">AlmaLinux·OS·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml">oval:ssg-installed_OS_is_almalinux9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·AlmaLinux·OS·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of42 configuration·settings·for·AlmaLinux·OS·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 131587, 15 lines modifiedOffset 131587, 15 lines modified
131587 ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>131587 ··············<xccdf-1.2:check-content-ref·href="ssg-almalinux9-ocil.xml"·name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>
131588 ············</xccdf-1.2:check>131588 ············</xccdf-1.2:check>
131589 ··········</xccdf-1.2:Rule>131589 ··········</xccdf-1.2:Rule>
131590 ········</xccdf-1.2:Group>131590 ········</xccdf-1.2:Group>
131591 ······</xccdf-1.2:Group>131591 ······</xccdf-1.2:Group>
131592 ····</xccdf-1.2:Benchmark>131592 ····</xccdf-1.2:Benchmark>
131593 ··</ds:component>131593 ··</ds:component>
131594 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-02-28T20:08:00">131594 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-oval.xml"·timestamp="2025-03-01T22:08:00">
131595 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">131595 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
131596 ······<oval-def:generator>131596 ······<oval-def:generator>
131597 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>131597 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
131598 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>131598 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
131599 ········<oval:schema_version>5.11</oval:schema_version>131599 ········<oval:schema_version>5.11</oval:schema_version>
131600 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>131600 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
131601 ······</oval-def:generator>131601 ······</oval-def:generator>
Offset 154336, 5268 lines modifiedOffset 154336, 5268 lines modified
154336 ············</oval-def:arithmetic>154336 ············</oval-def:arithmetic>
154337 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>154337 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
154338 ··········</oval-def:arithmetic>154338 ··········</oval-def:arithmetic>
154339 ········</oval-def:local_variable>154339 ········</oval-def:local_variable>
154340 ······</oval-def:variables>154340 ······</oval-def:variables>
154341 ····</oval-def:oval_definitions>154341 ····</oval-def:oval_definitions>
154342 ··</ds:component>154342 ··</ds:component>
154343 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-02-28T20:08:00">154343 ··<ds:component·id="scap_org.open-scap_comp_ssg-almalinux9-ocil.xml"·timestamp="2025-03-01T22:08:00">
154344 ····<ocil:ocil>154344 ····<ocil:ocil>
154345 ······<ocil:generator>154345 ······<ocil:generator>
154346 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>154346 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
154347 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>154347 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
154348 ········<ocil:schema_version>2.0</ocil:schema_version>154348 ········<ocil:schema_version>2.0</ocil:schema_version>
154349 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>154349 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
154350 ······</ocil:generator>154350 ······</ocil:generator>
154351 ······<ocil:questionnaires>154351 ······<ocil:questionnaires>
154352 ········<ocil:questionnaire·id="ocil:ssg-service_nftables_disabled_ocil:questionnaire:1"> 
154353 ··········<ocil:title>Verify·nftables·Service·is·Disabled</ocil:title> 
154354 ··········<ocil:actions> 
154355 ············<ocil:test_action_ref>ocil:ssg-service_nftables_disabled_action:testaction:1</ocil:test_action_ref> 
154356 ··········</ocil:actions> 
154357 ········</ocil:questionnaire> 
154358 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">154352 ········<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">
154359 ··········<ocil:title>Disable·SSH·Root·Login</ocil:title>154353 ··········<ocil:title>Remove·Rsh·Trust·Files</ocil:title>
154360 ··········<ocil:actions>154354 ··········<ocil:actions>
154361 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>154355 ············<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>
154362 ··········</ocil:actions>154356 ··········</ocil:actions>
154363 ········</ocil:questionnaire>154357 ········</ocil:questionnaire>
154364 ········<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1">154358 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">
154365 ··········<ocil:title>Enable·logrotate·Timer</ocil:title>154359 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>
154366 ··········<ocil:actions>154360 ··········<ocil:actions>
154367 ············<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref>154361 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>
154368 ··········</ocil:actions>154362 ··········</ocil:actions>
154369 ········</ocil:questionnaire>154363 ········</ocil:questionnaire>
154370 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">154364 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1">
154371 ··········<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>154365 ··········<ocil:title>Verify·Who·Owns·/etc/shells·File</ocil:title>
154372 ··········<ocil:actions>154366 ··········<ocil:actions>
154373 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>154367 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_shells_action:testaction:1</ocil:test_action_ref>
154374 ··········</ocil:actions>154368 ··········</ocil:actions>
154375 ········</ocil:questionnaire>154369 ········</ocil:questionnaire>
154376 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">154370 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">
154377 ··········<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>154371 ··········<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>
154378 ··········<ocil:actions>154372 ··········<ocil:actions>
154379 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>154373 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>
154380 ··········</ocil:actions>154374 ··········</ocil:actions>
154381 ········</ocil:questionnaire>154375 ········</ocil:questionnaire>
154382 ········<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">154376 ········<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
154383 ··········<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>154377 ··········<ocil:title>Uninstall·vsftpd·Package</ocil:title>
154384 ··········<ocil:actions>154378 ··········<ocil:actions>
154385 ············<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>154379 ············<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
154386 ··········</ocil:actions>154380 ··········</ocil:actions>
154387 ········</ocil:questionnaire>154381 ········</ocil:questionnaire>
154388 ········<ocil:questionnaire·id="ocil:ssg-package_talk-server_removed_ocil:questionnaire:1"> 
154389 ··········<ocil:title>Uninstall·talk-server·Package</ocil:title>154382 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_root_ocil:questionnaire:1">
 154383 ··········<ocil:title>Configure·the·root·Account·for·Failed·Password·Attempts</ocil:title>
154390 ··········<ocil:actions>154384 ··········<ocil:actions>
154391 ············<ocil:test_action_ref>ocil:ssg-package_talk-server_removed_action:testaction:1</ocil:test_action_ref>154385 ············<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_root_action:testaction:1</ocil:test_action_ref>
154392 ··········</ocil:actions>154386 ··········</ocil:actions>
154393 ········</ocil:questionnaire>154387 ········</ocil:questionnaire>
154394 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">154388 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">
154395 ··········<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>154389 ··········<ocil:title>Verify·Owner·on·cron.daily</ocil:title>
154396 ··········<ocil:actions>154390 ··········<ocil:actions>
154397 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>154391 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>
154398 ··········</ocil:actions>154392 ··········</ocil:actions>
154399 ········</ocil:questionnaire>154393 ········</ocil:questionnaire>
154400 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">154394 ········<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">
154401 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>154395 ··········<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>
154402 ··········<ocil:actions>154396 ··········<ocil:actions>
154403 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>154397 ············<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>
154404 ··········</ocil:actions>154398 ··········</ocil:actions>
154405 ········</ocil:questionnaire>154399 ········</ocil:questionnaire>
154406 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">154400 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">
154407 ··········<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>154401 ··········<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>
154408 ··········<ocil:actions>154402 ··········<ocil:actions>
154409 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>154403 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
154410 ··········</ocil:actions>154404 ··········</ocil:actions>
154411 ········</ocil:questionnaire>154405 ········</ocil:questionnaire>
154412 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">154406 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
154413 ··········<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>154407 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
154414 ··········<ocil:actions>154408 ··········<ocil:actions>
154415 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>154409 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
154416 ··········</ocil:actions>154410 ··········</ocil:actions>
154417 ········</ocil:questionnaire>154411 ········</ocil:questionnaire>
154418 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1"> 
154419 ··········<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>154412 ········<ocil:questionnaire·id="ocil:ssg-firewalld_loopback_traffic_trusted_ocil:questionnaire:1">
 154413 ··········<ocil:title>Configure·Firewalld·to·Trust·Loopback·Traffic</ocil:title>
154420 ··········<ocil:actions>154414 ··········<ocil:actions>
Max diff block lines reached; 1057219/1069376 bytes (98.86%) of diff not shown.
997 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
997 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
Ordering differences only
    
Offset 3, 5259 lines modifiedOffset 3, 5259 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_nftables_disabled_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·nftables·Service·is·Disabled</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-service_nftables_disabled_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>11 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">
23 ······<ocil:title>Enable·logrotate·Timer</ocil:title>17 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1">
29 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>23 ······<ocil:title>Verify·Who·Owns·/etc/shells·File</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shells_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">
35 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>29 ······<ocil:title>Restrict·usage·of·ptrace·to·descendant·processes</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
41 ······<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>35 ······<ocil:title>Uninstall·vsftpd·Package</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-package_talk-server_removed_ocil:questionnaire:1"> 
47 ······<ocil:title>Uninstall·talk-server·Package</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_root_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·the·root·Account·for·Failed·Password·Attempts</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-package_talk-server_removed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_root_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">
53 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>47 ······<ocil:title>Verify·Owner·on·cron.daily</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">
59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>53 ······<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>59 ······<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>65 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1"> 
77 ······<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-firewalld_loopback_traffic_trusted_ocil:questionnaire:1">
 71 ······<ocil:title>Configure·Firewalld·to·Trust·Loopback·Traffic</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-firewalld_loopback_traffic_trusted_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_ypserv_removed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1">
83 ······<ocil:title>Uninstall·ypserv·Package</ocil:title>77 ······<ocil:title>Add·nodev·Option·to·/dev/shm</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_ypserv_removed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>83 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_binaries_ocil:questionnaire:1">
 89 ······<ocil:title>Verify·that·audit·tools·are·owned·by·group·root</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_binaries_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-network_nmcli_permissions_ocil:questionnaire:1">
 95 ······<ocil:title>Prevent·non-Privileged·Users·from·Modifying·Network·Interfaces·using·nmcli</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-network_nmcli_permissions_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1"> 
107 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-package_audispd-plugins_installed_ocil:questionnaire:1">
113 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>107 ······<ocil:title>Install·audispd-plugins·Package</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-package_audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-dconf_db_up_to_date_ocil:questionnaire:1">
119 ······<ocil:title>User·Initialization·Files·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>113 ······<ocil:title>Make·sure·that·the·dconf·databases·are·up-to-date·with·regards·to·respective·keyfiles</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-dconf_db_up_to_date_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_umount_ocil:questionnaire:1">
Max diff block lines reached; 1008370/1020884 bytes (98.77%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 66305, 15 lines modifiedOffset 66305, 15 lines modified
66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis23-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
66306 ············</xccdf-1.2:check>66306 ············</xccdf-1.2:check>
66307 ··········</xccdf-1.2:Rule>66307 ··········</xccdf-1.2:Rule>
66308 ········</xccdf-1.2:Group>66308 ········</xccdf-1.2:Group>
66309 ······</xccdf-1.2:Group>66309 ······</xccdf-1.2:Group>
66310 ····</xccdf-1.2:Benchmark>66310 ····</xccdf-1.2:Benchmark>
66311 ··</ds:component>66311 ··</ds:component>
66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-02-28T20:08:00">66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-oval.xml"·timestamp="2025-03-01T22:08:00">
66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66314 ······<oval-def:generator>66314 ······<oval-def:generator>
66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
66317 ········<oval:schema_version>5.11</oval:schema_version>66317 ········<oval:schema_version>5.11</oval:schema_version>
66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66319 ······</oval-def:generator>66319 ······</oval-def:generator>
Offset 90165, 7084 lines modifiedOffset 90165, 6792 lines modified
90165 ············</oval-def:arithmetic>90165 ············</oval-def:arithmetic>
90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
90167 ··········</oval-def:arithmetic>90167 ··········</oval-def:arithmetic>
90168 ········</oval-def:local_variable>90168 ········</oval-def:local_variable>
90169 ······</oval-def:variables>90169 ······</oval-def:variables>
90170 ····</oval-def:oval_definitions>90170 ····</oval-def:oval_definitions>
90171 ··</ds:component>90171 ··</ds:component>
90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-02-28T20:08:00">90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-ocil.xml"·timestamp="2025-03-01T22:08:00">
90173 ····<ocil:ocil>90173 ····<ocil:ocil>
90174 ······<ocil:generator>90174 ······<ocil:generator>
90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
90177 ········<ocil:schema_version>2.0</ocil:schema_version>90177 ········<ocil:schema_version>2.0</ocil:schema_version>
90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
90179 ······</ocil:generator>90179 ······</ocil:generator>
90180 ······<ocil:questionnaires>90180 ······<ocil:questionnaires>
90181 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">90181 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1">
 90182 ··········<ocil:title>Ensure·All·SUID·Executables·Are·Authorized</ocil:title>
90182 ··········<ocil:title>Verify·Owner·on·cron.hourly</ocil:title> 
90183 ··········<ocil:actions> 
90184 ············<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref> 
90185 ··········</ocil:actions> 
90186 ········</ocil:questionnaire> 
90187 ········<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1"> 
90188 ··········<ocil:title>Install·AIDE</ocil:title> 
90189 ··········<ocil:actions> 
90190 ············<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref> 
90191 ··········</ocil:actions> 
90192 ········</ocil:questionnaire> 
90193 ········<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"> 
90194 ··········<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title> 
90195 ··········<ocil:actions>90183 ··········<ocil:actions>
90196 ············<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>90184 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>
90197 ··········</ocil:actions>90185 ··········</ocil:actions>
90198 ········</ocil:questionnaire>90186 ········</ocil:questionnaire>
90199 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">90187 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
90200 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>90188 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
90201 ··········<ocil:actions>90189 ··········<ocil:actions>
90202 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>90190 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
90203 ··········</ocil:actions>90191 ··········</ocil:actions>
90204 ········</ocil:questionnaire>90192 ········</ocil:questionnaire>
90205 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">90193 ········<ocil:questionnaire·id="ocil:ssg-service_squid_disabled_ocil:questionnaire:1">
90206 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>90194 ··········<ocil:title>Disable·Squid</ocil:title>
90207 ··········<ocil:actions>90195 ··········<ocil:actions>
90208 ············<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>90196 ············<ocil:test_action_ref>ocil:ssg-service_squid_disabled_action:testaction:1</ocil:test_action_ref>
90209 ··········</ocil:actions>90197 ··········</ocil:actions>
90210 ········</ocil:questionnaire>90198 ········</ocil:questionnaire>
90211 ········<ocil:questionnaire·id="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1">90199 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
90212 ··········<ocil:title>Ensure·that·System·Accounts·Do·Not·Run·a·Shell·Upon·Login</ocil:title>90200 ··········<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
90213 ··········<ocil:actions>90201 ··········<ocil:actions>
90214 ············<ocil:test_action_ref>ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1</ocil:test_action_ref>90202 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
90215 ··········</ocil:actions>90203 ··········</ocil:actions>
90216 ········</ocil:questionnaire>90204 ········</ocil:questionnaire>
90217 ········<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">90205 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
90218 ··········<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>90206 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
90219 ··········<ocil:actions>90207 ··········<ocil:actions>
90220 ············<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>90208 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
90221 ··········</ocil:actions>90209 ··········</ocil:actions>
90222 ········</ocil:questionnaire>90210 ········</ocil:questionnaire>
90223 ········<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">90211 ········<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">
90224 ··········<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>90212 ··········<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>
90225 ··········<ocil:actions>90213 ··········<ocil:actions>
90226 ············<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>90214 ············<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>
90227 ··········</ocil:actions>90215 ··········</ocil:actions>
90228 ········</ocil:questionnaire>90216 ········</ocil:questionnaire>
90229 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">90217 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">
90230 ··········<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>90218 ··········<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>
90231 ··········<ocil:actions>90219 ··········<ocil:actions>
90232 ············<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>90220 ············<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>
90233 ··········</ocil:actions>90221 ··········</ocil:actions>
90234 ········</ocil:questionnaire>90222 ········</ocil:questionnaire>
90235 ········<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1"> 
90236 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>90223 ········<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
 90224 ··········<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
90237 ··········<ocil:actions>90225 ··········<ocil:actions>
90238 ············<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>90226 ············<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
90239 ··········</ocil:actions>90227 ··········</ocil:actions>
90240 ········</ocil:questionnaire>90228 ········</ocil:questionnaire>
90241 ········<ocil:questionnaire·id="ocil:ssg-service_ypserv_disabled_ocil:questionnaire:1">90229 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
90242 ··········<ocil:title>Disable·ypserv·Service</ocil:title>90230 ··········<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
90243 ··········<ocil:actions>90231 ··········<ocil:actions>
90244 ············<ocil:test_action_ref>ocil:ssg-service_ypserv_disabled_action:testaction:1</ocil:test_action_ref>90232 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
90245 ··········</ocil:actions>90233 ··········</ocil:actions>
90246 ········</ocil:questionnaire>90234 ········</ocil:questionnaire>
90247 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">90235 ········<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
90248 ··········<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>90236 ··········<ocil:title>Set·Interactive·Session·Timeout</ocil:title>
90249 ··········<ocil:actions>90237 ··········<ocil:actions>
Max diff block lines reached; 1044876/1056452 bytes (98.90%) of diff not shown.
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
Ordering differences only
    
Offset 3, 7075 lines modifiedOffset 3, 6783 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·All·SUID·Executables·Are·Authorized</ocil:title>
11 ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1"> 
17 ······<ocil:title>Install·AIDE</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"> 
23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>17 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-service_squid_disabled_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>23 ······<ocil:title>Disable·Squid</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-service_squid_disabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·that·System·Accounts·Do·Not·Run·a·Shell·Upon·Login</ocil:title>29 ······<ocil:title>Configure·Polyinstantiation·of·/tmp·Directories</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>35 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">
53 ······<ocil:title>Verify·ip6tables·Enabled·if·Using·IPv6</ocil:title>41 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">
59 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>47 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-service_ypserv_disabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
71 ······<ocil:title>Disable·ypserv·Service</ocil:title>59 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-service_ypserv_disabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
77 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>65 ······<ocil:title>Set·Interactive·Session·Timeout</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1"> 
83 ······<ocil:title>Enable·checks·on·credential·management</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·User</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>77 ······<ocil:title>Disable·support·for·/proc/kkcore</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_proc_kcore_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·All·SUID·Executables·Are·Authorized</ocil:title>83 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>89 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-service_smb_disabled_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·Samba</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-service_smb_disabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1"> 
113 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"> 
119 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
123 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
Max diff block lines reached; 996632/1008642 bytes (98.81%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 66305, 15 lines modifiedOffset 66305, 15 lines modified
66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>66305 ··············<xccdf-1.2:check-content-ref·href="ssg-anolis8-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
66306 ············</xccdf-1.2:check>66306 ············</xccdf-1.2:check>
66307 ··········</xccdf-1.2:Rule>66307 ··········</xccdf-1.2:Rule>
66308 ········</xccdf-1.2:Group>66308 ········</xccdf-1.2:Group>
66309 ······</xccdf-1.2:Group>66309 ······</xccdf-1.2:Group>
66310 ····</xccdf-1.2:Benchmark>66310 ····</xccdf-1.2:Benchmark>
66311 ··</ds:component>66311 ··</ds:component>
66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-02-28T20:08:00">66312 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-oval.xml"·timestamp="2025-03-01T22:08:00">
66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66313 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66314 ······<oval-def:generator>66314 ······<oval-def:generator>
66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66315 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>66316 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
66317 ········<oval:schema_version>5.11</oval:schema_version>66317 ········<oval:schema_version>5.11</oval:schema_version>
66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66318 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66319 ······</oval-def:generator>66319 ······</oval-def:generator>
Offset 90165, 4750 lines modifiedOffset 90165, 4750 lines modified
90165 ············</oval-def:arithmetic>90165 ············</oval-def:arithmetic>
90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>90166 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
90167 ··········</oval-def:arithmetic>90167 ··········</oval-def:arithmetic>
90168 ········</oval-def:local_variable>90168 ········</oval-def:local_variable>
90169 ······</oval-def:variables>90169 ······</oval-def:variables>
90170 ····</oval-def:oval_definitions>90170 ····</oval-def:oval_definitions>
90171 ··</ds:component>90171 ··</ds:component>
90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-02-28T20:08:00">90172 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-ocil.xml"·timestamp="2025-03-01T22:08:00">
90173 ····<ocil:ocil>90173 ····<ocil:ocil>
90174 ······<ocil:generator>90174 ······<ocil:generator>
90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>90175 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>90176 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
90177 ········<ocil:schema_version>2.0</ocil:schema_version>90177 ········<ocil:schema_version>2.0</ocil:schema_version>
90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>90178 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
90179 ······</ocil:generator>90179 ······</ocil:generator>
90180 ······<ocil:questionnaires>90180 ······<ocil:questionnaires>
90181 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1"> 
90182 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title> 
90183 ··········<ocil:actions> 
90184 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
90185 ··········</ocil:actions> 
90186 ········</ocil:questionnaire> 
90187 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">90181 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">
90188 ··········<ocil:title>Enable·module·signature·verification</ocil:title>90182 ··········<ocil:title>Enable·GSSAPI·Authentication</ocil:title>
90189 ··········<ocil:actions>90183 ··········<ocil:actions>
90190 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>90184 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
90191 ··········</ocil:actions>90185 ··········</ocil:actions>
90192 ········</ocil:questionnaire>90186 ········</ocil:questionnaire>
90193 ········<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">90187 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">
90194 ··········<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>90188 ··········<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>
90195 ··········<ocil:actions>90189 ··········<ocil:actions>
90196 ············<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>90190 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>
90197 ··········</ocil:actions>90191 ··········</ocil:actions>
90198 ········</ocil:questionnaire>90192 ········</ocil:questionnaire>
90199 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> 
90200 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·truncate</ocil:title>90193 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1">
 90194 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</ocil:title>
90201 ··········<ocil:actions>90195 ··········<ocil:actions>
90202 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>90196 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>
90203 ··········</ocil:actions>90197 ··········</ocil:actions>
90204 ········</ocil:questionnaire>90198 ········</ocil:questionnaire>
90205 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> 
90206 ··········<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>90199 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 90200 ··········<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
90207 ··········<ocil:actions>90201 ··········<ocil:actions>
90208 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>90202 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
90209 ··········</ocil:actions>90203 ··········</ocil:actions>
90210 ········</ocil:questionnaire>90204 ········</ocil:questionnaire>
90211 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">90205 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
90212 ··········<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>90206 ··········<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
90213 ··········<ocil:actions>90207 ··········<ocil:actions>
90214 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>90208 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
90215 ··········</ocil:actions>90209 ··········</ocil:actions>
90216 ········</ocil:questionnaire>90210 ········</ocil:questionnaire>
90217 ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">90211 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
90218 ··········<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title>90212 ··········<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>
90219 ··········<ocil:actions>90213 ··········<ocil:actions>
90220 ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>90214 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>
90221 ··········</ocil:actions>90215 ··········</ocil:actions>
90222 ········</ocil:questionnaire>90216 ········</ocil:questionnaire>
90223 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">90217 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
90224 ··········<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>90218 ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title>
90225 ··········<ocil:actions>90219 ··········<ocil:actions>
90226 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>90220 ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
90227 ··········</ocil:actions>90221 ··········</ocil:actions>
90228 ········</ocil:questionnaire>90222 ········</ocil:questionnaire>
90229 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">90223 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
90230 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>90224 ··········<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
90231 ··········<ocil:actions>90225 ··········<ocil:actions>
90232 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>90226 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
90233 ··········</ocil:actions>90227 ··········</ocil:actions>
90234 ········</ocil:questionnaire>90228 ········</ocil:questionnaire>
90235 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_d_ocil:questionnaire:1">90229 ········<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
90236 ··········<ocil:title>Verify·Permissions·on·cron.d</ocil:title>90230 ··········<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>
90237 ··········<ocil:actions>90231 ··········<ocil:actions>
90238 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_d_action:testaction:1</ocil:test_action_ref>90232 ············<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
90239 ··········</ocil:actions>90233 ··········</ocil:actions>
90240 ········</ocil:questionnaire>90234 ········</ocil:questionnaire>
90241 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">90235 ········<ocil:questionnaire·id="ocil:ssg-configure_crypto_policy_ocil:questionnaire:1">
90242 ··········<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>90236 ··········<ocil:title>Configure·System·Cryptography·Policy</ocil:title>
90243 ··········<ocil:actions>90237 ··········<ocil:actions>
90244 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>90238 ············<ocil:test_action_ref>ocil:ssg-configure_crypto_policy_action:testaction:1</ocil:test_action_ref>
90245 ··········</ocil:actions>90239 ··········</ocil:actions>
90246 ········</ocil:questionnaire>90240 ········</ocil:questionnaire>
90247 ········<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">90241 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
90248 ··········<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>90242 ··········<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>
90249 ··········<ocil:actions>90243 ··········<ocil:actions>
Max diff block lines reached; 1043836/1055808 bytes (98.87%) of diff not shown.
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
Ordering differences only
    
Offset 3, 4741 lines modifiedOffset 3, 4741 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv6·Interfaces</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">
17 ······<ocil:title>Enable·module·signature·verification</ocil:title>11 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">
23 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"> 
29 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·truncate</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"> 
35 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·ftruncate</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 29 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>35 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·yum·Configuration</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
53 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>47 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
59 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>53 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_d_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Permissions·on·cron.d</ocil:title>59 ······<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_d_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-configure_crypto_policy_ocil:questionnaire:1">
71 ······<ocil:title>Set·SSH·MaxSessions·limit</ocil:title>65 ······<ocil:title>Configure·System·Cryptography·Policy</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-configure_crypto_policy_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
77 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title>71 ······<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_ocil:questionnaire:1">
83 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>77 ······<ocil:title>Configure·Accepting·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
89 ······<ocil:title>Disable·SSH·Server·If·Possible</ocil:title>83 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-service_sshd_disabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
95 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>89 ······<ocil:title>Enable·auditd·Service</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title>95 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"> 
107 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-service_httpd_disabled_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·httpd·Service</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_httpd_disabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
119 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>113 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1">
Max diff block lines reached; 995562/1008004 bytes (98.77%) of diff not shown.
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 75, 15 lines modifiedOffset 75, 15 lines modified
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">76 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:8">
77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>77 ········<cpe-dict:title·xml:lang="en-us">CentOS·8</cpe-dict:title>
78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>78 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_centos8:def:1</cpe-dict:check>
79 ······</cpe-dict:cpe-item>79 ······</cpe-dict:cpe-item>
80 ····</cpe-dict:cpe-list>80 ····</cpe-dict:cpe-list>
81 ··</ds:component>81 ··</ds:component>
82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">82 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">83 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>84 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>85 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
86 ······<xccdf-1.2:description>86 ······<xccdf-1.2:description>
87 ········This·guide·presents·a·catalog·of·security-relevant87 ········This·guide·presents·a·catalog·of·security-relevant
88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of88 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)89 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 312766, 15 lines modifiedOffset 312766, 15 lines modified
312766 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>312766 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
312767 ············</xccdf-1.2:check>312767 ············</xccdf-1.2:check>
312768 ··········</xccdf-1.2:Rule>312768 ··········</xccdf-1.2:Rule>
312769 ········</xccdf-1.2:Group>312769 ········</xccdf-1.2:Group>
312770 ······</xccdf-1.2:Group>312770 ······</xccdf-1.2:Group>
312771 ····</xccdf-1.2:Benchmark>312771 ····</xccdf-1.2:Benchmark>
312772 ··</ds:component>312772 ··</ds:component>
312773 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-02-28T20:08:00">312773 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00">
312774 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">312774 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
312775 ······<oval-def:generator>312775 ······<oval-def:generator>
312776 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>312776 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
312777 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>312777 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
312778 ········<oval:schema_version>5.11</oval:schema_version>312778 ········<oval:schema_version>5.11</oval:schema_version>
312779 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>312779 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
312780 ······</oval-def:generator>312780 ······</oval-def:generator>
Offset 379152, 11327 lines modifiedOffset 379152, 11327 lines modified
379152 ············</oval-def:arithmetic>379152 ············</oval-def:arithmetic>
379153 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>379153 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
379154 ··········</oval-def:arithmetic>379154 ··········</oval-def:arithmetic>
379155 ········</oval-def:local_variable>379155 ········</oval-def:local_variable>
379156 ······</oval-def:variables>379156 ······</oval-def:variables>
379157 ····</oval-def:oval_definitions>379157 ····</oval-def:oval_definitions>
379158 ··</ds:component>379158 ··</ds:component>
379159 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-02-28T20:08:00">379159 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00">
379160 ····<ocil:ocil>379160 ····<ocil:ocil>
379161 ······<ocil:generator>379161 ······<ocil:generator>
379162 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>379162 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
379163 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>379163 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
379164 ········<ocil:schema_version>2.0</ocil:schema_version>379164 ········<ocil:schema_version>2.0</ocil:schema_version>
379165 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>379165 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
379166 ······</ocil:generator>379166 ······</ocil:generator>
379167 ······<ocil:questionnaires>379167 ······<ocil:questionnaires>
379168 ········<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1"> 
379169 ··········<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>379168 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwquality_system_auth_ocil:questionnaire:1">
 379169 ··········<ocil:title>Ensure·PAM·password·complexity·module·is·enabled·in·system-auth</ocil:title>
379170 ··········<ocil:actions>379170 ··········<ocil:actions>
379171 ············<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>379171 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwquality_system_auth_action:testaction:1</ocil:test_action_ref>
379172 ··········</ocil:actions>379172 ··········</ocil:actions>
379173 ········</ocil:questionnaire>379173 ········</ocil:questionnaire>
379174 ········<ocil:questionnaire·id="ocil:ssg-zipl_enable_selinux_ocil:questionnaire:1">379174 ········<ocil:questionnaire·id="ocil:ssg-httpd_antivirus_scan_uploads_ocil:questionnaire:1">
379175 ··········<ocil:title>Ensure·SELinux·Not·Disabled·in·zIPL</ocil:title>379175 ··········<ocil:title>Scan·All·Uploaded·Content·for·Malicious·Software</ocil:title>
379176 ··········<ocil:actions>379176 ··········<ocil:actions>
379177 ············<ocil:test_action_ref>ocil:ssg-zipl_enable_selinux_action:testaction:1</ocil:test_action_ref>379177 ············<ocil:test_action_ref>ocil:ssg-httpd_antivirus_scan_uploads_action:testaction:1</ocil:test_action_ref>
379178 ··········</ocil:actions>379178 ··········</ocil:actions>
379179 ········</ocil:questionnaire>379179 ········</ocil:questionnaire>
379180 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">379180 ········<ocil:questionnaire·id="ocil:ssg-sebool_deny_ptrace_ocil:questionnaire:1">
379181 ··········<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>379181 ··········<ocil:title>Disable·the·deny_ptrace·SELinux·Boolean</ocil:title>
379182 ··········<ocil:actions>379182 ··········<ocil:actions>
379183 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>379183 ············<ocil:test_action_ref>ocil:ssg-sebool_deny_ptrace_action:testaction:1</ocil:test_action_ref>
379184 ··········</ocil:actions>379184 ··········</ocil:actions>
379185 ········</ocil:questionnaire>379185 ········</ocil:questionnaire>
379186 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">379186 ········<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1">
379187 ··········<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>379187 ··········<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title>
379188 ··········<ocil:actions>379188 ··········<ocil:actions>
379189 ············<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>379189 ············<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>
379190 ··········</ocil:actions>379190 ··········</ocil:actions>
379191 ········</ocil:questionnaire>379191 ········</ocil:questionnaire>
379192 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1"> 
379193 ··········<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·open·Are·Ordered·Correctly</ocil:title>379192 ········<ocil:questionnaire·id="ocil:ssg-sebool_cups_execmem_ocil:questionnaire:1">
 379193 ··········<ocil:title>Disable·the·cups_execmem·SELinux·Boolean</ocil:title>
379194 ··········<ocil:actions>379194 ··········<ocil:actions>
379195 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_action:testaction:1</ocil:test_action_ref>379195 ············<ocil:test_action_ref>ocil:ssg-sebool_cups_execmem_action:testaction:1</ocil:test_action_ref>
379196 ··········</ocil:actions>379196 ··········</ocil:actions>
379197 ········</ocil:questionnaire>379197 ········</ocil:questionnaire>
379198 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_on_data_corruption_ocil:questionnaire:1">379198 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_autorun_ocil:questionnaire:1">
379199 ··········<ocil:title>Trigger·a·kernel·BUG·when·data·corruption·is·detected</ocil:title>379199 ··········<ocil:title>Disable·GNOME3·Automount·running</ocil:title>
379200 ··········<ocil:actions>379200 ··········<ocil:actions>
379201 ············<ocil:test_action_ref>ocil:ssg-kernel_config_bug_on_data_corruption_action:testaction:1</ocil:test_action_ref>379201 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_autorun_action:testaction:1</ocil:test_action_ref>
379202 ··········</ocil:actions>379202 ··········</ocil:actions>
379203 ········</ocil:questionnaire>379203 ········</ocil:questionnaire>
379204 ········<ocil:questionnaire·id="ocil:ssg-service_abrtd_disabled_ocil:questionnaire:1">379204 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
379205 ··········<ocil:title>Disable·Automatic·Bug·Reporting·Tool·(abrtd)</ocil:title>379205 ··········<ocil:title>Enable·Public·Key·Authentication</ocil:title>
379206 ··········<ocil:actions>379206 ··········<ocil:actions>
379207 ············<ocil:test_action_ref>ocil:ssg-service_abrtd_disabled_action:testaction:1</ocil:test_action_ref>379207 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
379208 ··········</ocil:actions>379208 ··········</ocil:actions>
379209 ········</ocil:questionnaire>379209 ········</ocil:questionnaire>
379210 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_restorecon_ocil:questionnaire:1">379210 ········<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">
379211 ··········<ocil:title>Record·Any·Attempts·to·Run·restorecon</ocil:title>379211 ··········<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>
379212 ··········<ocil:actions>379212 ··········<ocil:actions>
379213 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_restorecon_action:testaction:1</ocil:test_action_ref>379213 ············<ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>
379214 ··········</ocil:actions>379214 ··········</ocil:actions>
379215 ········</ocil:questionnaire>379215 ········</ocil:questionnaire>
379216 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_grpquota_ocil:questionnaire:1">379216 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_tmp_ocil:questionnaire:1">
379217 ··········<ocil:title>Add·grpquota·Option·to·/home</ocil:title>379217 ··········<ocil:title>Ensure·/var/tmp·Located·On·Separate·Partition</ocil:title>
379218 ··········<ocil:actions>379218 ··········<ocil:actions>
379219 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_grpquota_action:testaction:1</ocil:test_action_ref>379219 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_tmp_action:testaction:1</ocil:test_action_ref>
379220 ··········</ocil:actions>379220 ··········</ocil:actions>
379221 ········</ocil:questionnaire>379221 ········</ocil:questionnaire>
379222 ········<ocil:questionnaire·id="ocil:ssg-encrypt_partitions_ocil:questionnaire:1">379222 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">
379223 ··········<ocil:title>Encrypt·Partitions</ocil:title>379223 ··········<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>
379224 ··········<ocil:actions>379224 ··········<ocil:actions>
379225 ············<ocil:test_action_ref>ocil:ssg-encrypt_partitions_action:testaction:1</ocil:test_action_ref>379225 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>
379226 ··········</ocil:actions>379226 ··········</ocil:actions>
379227 ········</ocil:questionnaire>379227 ········</ocil:questionnaire>
379228 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">379228 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
Max diff block lines reached; 3565659/3577436 bytes (99.67%) of diff not shown.
2.13 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
2.13 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:10">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·10</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_centos10:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 366, 25 lines modifiedOffset 366, 25 lines modified
366 ··········</cpe-lang:logical-test>366 ··········</cpe-lang:logical-test>
367 ········</cpe-lang:platform>367 ········</cpe-lang:platform>
368 ········<cpe-lang:platform·id="package_bash">368 ········<cpe-lang:platform·id="package_bash">
369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
371 ··········</cpe-lang:logical-test>371 ··········</cpe-lang:logical-test>
372 ········</cpe-lang:platform>372 ········</cpe-lang:platform>
373 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
374 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
376 ··········</cpe-lang:logical-test> 
377 ········</cpe-lang:platform> 
378 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">373 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
379 ··········<cpe-lang:logical-test·operator="AND"·negate="false">374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
380 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
381 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>376 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
382 ··········</cpe-lang:logical-test>377 ··········</cpe-lang:logical-test>
383 ········</cpe-lang:platform>378 ········</cpe-lang:platform>
 379 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 380 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 381 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 382 ··········</cpe-lang:logical-test>
 383 ········</cpe-lang:platform>
384 ········<cpe-lang:platform·id="not_s390x_arch">384 ········<cpe-lang:platform·id="not_s390x_arch">
385 ··········<cpe-lang:logical-test·operator="AND"·negate="false">385 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
386 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>386 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
387 ··········</cpe-lang:logical-test>387 ··········</cpe-lang:logical-test>
388 ········</cpe-lang:platform>388 ········</cpe-lang:platform>
389 ········<cpe-lang:platform·id="package_tmux">389 ········<cpe-lang:platform·id="package_tmux">
390 ··········<cpe-lang:logical-test·operator="AND"·negate="false">390 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 213008, 15 lines modifiedOffset 213008, 15 lines modified
213008 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>213008 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>
213009 ············</xccdf-1.2:check>213009 ············</xccdf-1.2:check>
213010 ··········</xccdf-1.2:Rule>213010 ··········</xccdf-1.2:Rule>
213011 ········</xccdf-1.2:Group>213011 ········</xccdf-1.2:Group>
213012 ······</xccdf-1.2:Group>213012 ······</xccdf-1.2:Group>
213013 ····</xccdf-1.2:Benchmark>213013 ····</xccdf-1.2:Benchmark>
213014 ··</ds:component>213014 ··</ds:component>
213015 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-02-28T20:08:00">213015 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00">
213016 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">213016 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
213017 ······<oval-def:generator>213017 ······<oval-def:generator>
213018 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>213018 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
213019 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>213019 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
213020 ········<oval:schema_version>5.11</oval:schema_version>213020 ········<oval:schema_version>5.11</oval:schema_version>
213021 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>213021 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
213022 ······</oval-def:generator>213022 ······</oval-def:generator>
Offset 261685, 6855 lines modifiedOffset 261685, 6855 lines modified
261685 ············</oval-def:arithmetic>261685 ············</oval-def:arithmetic>
261686 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>261686 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
261687 ··········</oval-def:arithmetic>261687 ··········</oval-def:arithmetic>
261688 ········</oval-def:local_variable>261688 ········</oval-def:local_variable>
261689 ······</oval-def:variables>261689 ······</oval-def:variables>
261690 ····</oval-def:oval_definitions>261690 ····</oval-def:oval_definitions>
261691 ··</ds:component>261691 ··</ds:component>
261692 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-02-28T20:08:00">261692 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00">
261693 ····<ocil:ocil>261693 ····<ocil:ocil>
261694 ······<ocil:generator>261694 ······<ocil:generator>
261695 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>261695 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
261696 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>261696 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
261697 ········<ocil:schema_version>2.0</ocil:schema_version>261697 ········<ocil:schema_version>2.0</ocil:schema_version>
261698 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>261698 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
261699 ······</ocil:generator>261699 ······</ocil:generator>
261700 ······<ocil:questionnaires>261700 ······<ocil:questionnaires>
 261701 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_ocil:questionnaire:1">
 261702 ··········<ocil:title>Set·number·of·Password·Hashing·Rounds·-·system-auth</ocil:title>
261701 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1"> 
261702 ··········<ocil:title>Verify·Permissions·On·/etc/sudoers·File</ocil:title> 
261703 ··········<ocil:actions> 
261704 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_sudoers_action:testaction:1</ocil:test_action_ref> 
261705 ··········</ocil:actions> 
261706 ········</ocil:questionnaire> 
261707 ········<ocil:questionnaire·id="ocil:ssg-grub2_audit_backlog_limit_argument_ocil:questionnaire:1"> 
261708 ··········<ocil:title>Extend·Audit·Backlog·Limit·for·the·Audit·Daemon</ocil:title> 
261709 ··········<ocil:actions> 
261710 ············<ocil:test_action_ref>ocil:ssg-grub2_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref> 
261711 ··········</ocil:actions> 
261712 ········</ocil:questionnaire> 
261713 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_ocil:questionnaire:1"> 
261714 ··········<ocil:title>Set·Kernel·Parameter·to·Increase·Local·Port·Range</ocil:title> 
261715 ··········<ocil:actions> 
261716 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_local_port_range_action:testaction:1</ocil:test_action_ref> 
261717 ··········</ocil:actions> 
261718 ········</ocil:questionnaire> 
261719 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1"> 
261720 ··········<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title> 
261721 ··········<ocil:actions>261703 ··········<ocil:actions>
261722 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>261704 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_rounds_system_auth_action:testaction:1</ocil:test_action_ref>
261723 ··········</ocil:actions>261705 ··········</ocil:actions>
261724 ········</ocil:questionnaire>261706 ········</ocil:questionnaire>
261725 ········<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">261707 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
261726 ··········<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>261708 ··········<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
261727 ··········<ocil:actions>261709 ··········<ocil:actions>
261728 ············<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>261710 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
261729 ··········</ocil:actions>261711 ··········</ocil:actions>
261730 ········</ocil:questionnaire>261712 ········</ocil:questionnaire>
261731 ········<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">261713 ········<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
261732 ··········<ocil:title>Uninstall·vsftpd·Package</ocil:title>261714 ··········<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title>
261733 ··········<ocil:actions>261715 ··········<ocil:actions>
261734 ············<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>261716 ············<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 2228199/2238222 bytes (99.55%) of diff not shown.
2.29 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
2.19 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
Ordering differences only
    
Offset 329, 25 lines modifiedOffset 329, 25 lines modified
329 ······</cpe-lang:logical-test>329 ······</cpe-lang:logical-test>
330 ····</cpe-lang:platform>330 ····</cpe-lang:platform>
331 ····<cpe-lang:platform·id="package_bash">331 ····<cpe-lang:platform·id="package_bash">
332 ······<cpe-lang:logical-test·operator="AND"·negate="false">332 ······<cpe-lang:logical-test·operator="AND"·negate="false">
333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
334 ······</cpe-lang:logical-test>334 ······</cpe-lang:logical-test>
335 ····</cpe-lang:platform>335 ····</cpe-lang:platform>
336 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
337 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
338 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
339 ······</cpe-lang:logical-test> 
340 ····</cpe-lang:platform> 
341 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">336 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
342 ······<cpe-lang:logical-test·operator="AND"·negate="false">337 ······<cpe-lang:logical-test·operator="AND"·negate="false">
343 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>338 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
345 ······</cpe-lang:logical-test>340 ······</cpe-lang:logical-test>
346 ····</cpe-lang:platform>341 ····</cpe-lang:platform>
 342 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 343 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 345 ······</cpe-lang:logical-test>
 346 ····</cpe-lang:platform>
347 ····<cpe-lang:platform·id="not_s390x_arch">347 ····<cpe-lang:platform·id="not_s390x_arch">
348 ······<cpe-lang:logical-test·operator="AND"·negate="false">348 ······<cpe-lang:logical-test·operator="AND"·negate="false">
349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
350 ······</cpe-lang:logical-test>350 ······</cpe-lang:logical-test>
351 ····</cpe-lang:platform>351 ····</cpe-lang:platform>
352 ····<cpe-lang:platform·id="package_tmux">352 ····<cpe-lang:platform·id="package_tmux">
353 ······<cpe-lang:logical-test·operator="AND"·negate="false">353 ······<cpe-lang:logical-test·operator="AND"·negate="false">
3.26 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
3.26 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">32 ······<cpe-dict:cpe-item·name="cpe:/o:centos:centos:9">
33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">CentOS·Stream·9</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_centos9:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 433, 23 lines modifiedOffset 433, 23 lines modified
433 ··········</cpe-lang:logical-test>433 ··········</cpe-lang:logical-test>
434 ········</cpe-lang:platform>434 ········</cpe-lang:platform>
435 ········<cpe-lang:platform·id="package_bash">435 ········<cpe-lang:platform·id="package_bash">
436 ··········<cpe-lang:logical-test·operator="AND"·negate="false">436 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
437 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>437 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
438 ··········</cpe-lang:logical-test>438 ··········</cpe-lang:logical-test>
439 ········</cpe-lang:platform>439 ········</cpe-lang:platform>
440 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">440 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
441 ··········<cpe-lang:logical-test·operator="AND"·negate="false">441 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
442 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>442 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
443 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
444 ··········</cpe-lang:logical-test>443 ··········</cpe-lang:logical-test>
445 ········</cpe-lang:platform>444 ········</cpe-lang:platform>
446 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">445 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
447 ··········<cpe-lang:logical-test·operator="AND"·negate="false">446 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
448 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>447 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 448 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
449 ··········</cpe-lang:logical-test>449 ··········</cpe-lang:logical-test>
450 ········</cpe-lang:platform>450 ········</cpe-lang:platform>
451 ········<cpe-lang:platform·id="not_s390x_arch">451 ········<cpe-lang:platform·id="not_s390x_arch">
452 ··········<cpe-lang:logical-test·operator="AND"·negate="false">452 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
453 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>453 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
454 ··········</cpe-lang:logical-test>454 ··········</cpe-lang:logical-test>
455 ········</cpe-lang:platform>455 ········</cpe-lang:platform>
Offset 305658, 15 lines modifiedOffset 305658, 15 lines modified
305658 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>305658 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
305659 ············</xccdf-1.2:check>305659 ············</xccdf-1.2:check>
305660 ··········</xccdf-1.2:Rule>305660 ··········</xccdf-1.2:Rule>
305661 ········</xccdf-1.2:Group>305661 ········</xccdf-1.2:Group>
305662 ······</xccdf-1.2:Group>305662 ······</xccdf-1.2:Group>
305663 ····</xccdf-1.2:Benchmark>305663 ····</xccdf-1.2:Benchmark>
305664 ··</ds:component>305664 ··</ds:component>
305665 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-02-28T20:08:00">305665 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00">
305666 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">305666 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
305667 ······<oval-def:generator>305667 ······<oval-def:generator>
305668 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>305668 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
305669 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>305669 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
305670 ········<oval:schema_version>5.11</oval:schema_version>305670 ········<oval:schema_version>5.11</oval:schema_version>
305671 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>305671 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
305672 ······</oval-def:generator>305672 ······</oval-def:generator>
Offset 371382, 22912 lines modifiedOffset 371382, 22125 lines modified
371382 ············</oval-def:arithmetic>371382 ············</oval-def:arithmetic>
371383 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>371383 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
371384 ··········</oval-def:arithmetic>371384 ··········</oval-def:arithmetic>
371385 ········</oval-def:local_variable>371385 ········</oval-def:local_variable>
371386 ······</oval-def:variables>371386 ······</oval-def:variables>
371387 ····</oval-def:oval_definitions>371387 ····</oval-def:oval_definitions>
371388 ··</ds:component>371388 ··</ds:component>
371389 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-02-28T20:08:00">371389 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00">
371390 ····<ocil:ocil>371390 ····<ocil:ocil>
371391 ······<ocil:generator>371391 ······<ocil:generator>
371392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>371392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
371393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>371393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
371394 ········<ocil:schema_version>2.0</ocil:schema_version>371394 ········<ocil:schema_version>2.0</ocil:schema_version>
371395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>371395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
371396 ······</ocil:generator>371396 ······</ocil:generator>
371397 ······<ocil:questionnaires>371397 ······<ocil:questionnaires>
371398 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1"> 
371399 ··········<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title> 
371400 ··········<ocil:actions> 
371401 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref> 
371402 ··········</ocil:actions> 
371403 ········</ocil:questionnaire> 
371404 ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> 
371405 ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title> 
371406 ··········<ocil:actions> 
371407 ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref> 
371408 ··········</ocil:actions> 
371409 ········</ocil:questionnaire> 
371410 ········<ocil:questionnaire·id="ocil:ssg-accounts_have_homedir_login_defs_ocil:questionnaire:1"> 
371411 ··········<ocil:title>Ensure·Home·Directories·are·Created·for·New·Users</ocil:title> 
371412 ··········<ocil:actions> 
371413 ············<ocil:test_action_ref>ocil:ssg-accounts_have_homedir_login_defs_action:testaction:1</ocil:test_action_ref> 
371414 ··········</ocil:actions> 
371415 ········</ocil:questionnaire> 
371416 ········<ocil:questionnaire·id="ocil:ssg-zipl_bootmap_is_up_to_date_ocil:questionnaire:1">371398 ········<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1">
371417 ··········<ocil:title>Ensure·zIPL·bootmap·is·up·to·date</ocil:title>371399 ··········<ocil:title>Prevent·remote·hosts·from·connecting·to·the·proxy·display</ocil:title>
371418 ··········<ocil:actions>371400 ··········<ocil:actions>
371419 ············<ocil:test_action_ref>ocil:ssg-zipl_bootmap_is_up_to_date_action:testaction:1</ocil:test_action_ref>371401 ············<ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref>
371420 ··········</ocil:actions>371402 ··········</ocil:actions>
371421 ········</ocil:questionnaire>371403 ········</ocil:questionnaire>
371422 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">371404 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
371423 ··········<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>371405 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
371424 ··········<ocil:actions>371406 ··········<ocil:actions>
371425 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>371407 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
371426 ··········</ocil:actions>371408 ··········</ocil:actions>
371427 ········</ocil:questionnaire>371409 ········</ocil:questionnaire>
371428 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1">371410 ········<ocil:questionnaire·id="ocil:ssg-package_samba-common_installed_ocil:questionnaire:1">
371429 ··········<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>371411 ··········<ocil:title>Install·the·Samba·Common·Package</ocil:title>
371430 ··········<ocil:actions>371412 ··········<ocil:actions>
371431 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>371413 ············<ocil:test_action_ref>ocil:ssg-package_samba-common_installed_action:testaction:1</ocil:test_action_ref>
371432 ··········</ocil:actions>371414 ··········</ocil:actions>
371433 ········</ocil:questionnaire>371415 ········</ocil:questionnaire>
371434 ········<ocil:questionnaire·id="ocil:ssg-audit_owner_change_failed_ppc64le_ocil:questionnaire:1">371416 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
371435 ··········<ocil:title>Configure·auditing·of·unsuccessful·ownership·changes·(ppc64le)</ocil:title>371417 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
371436 ··········<ocil:actions>371418 ··········<ocil:actions>
371437 ············<ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_ppc64le_action:testaction:1</ocil:test_action_ref>371419 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
371438 ··········</ocil:actions>371420 ··········</ocil:actions>
371439 ········</ocil:questionnaire>371421 ········</ocil:questionnaire>
Max diff block lines reached; 3403978/3415309 bytes (99.67%) of diff not shown.
2.48 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
2.39 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
Ordering differences only
    
Offset 396, 23 lines modifiedOffset 396, 23 lines modified
396 ······</cpe-lang:logical-test>396 ······</cpe-lang:logical-test>
397 ····</cpe-lang:platform>397 ····</cpe-lang:platform>
398 ····<cpe-lang:platform·id="package_bash">398 ····<cpe-lang:platform·id="package_bash">
399 ······<cpe-lang:logical-test·operator="AND"·negate="false">399 ······<cpe-lang:logical-test·operator="AND"·negate="false">
400 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>400 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
401 ······</cpe-lang:logical-test>401 ······</cpe-lang:logical-test>
402 ····</cpe-lang:platform>402 ····</cpe-lang:platform>
403 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">403 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
404 ······<cpe-lang:logical-test·operator="AND"·negate="false">404 ······<cpe-lang:logical-test·operator="AND"·negate="false">
405 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>405 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
406 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
407 ······</cpe-lang:logical-test>406 ······</cpe-lang:logical-test>
408 ····</cpe-lang:platform>407 ····</cpe-lang:platform>
409 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">408 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
410 ······<cpe-lang:logical-test·operator="AND"·negate="false">409 ······<cpe-lang:logical-test·operator="AND"·negate="false">
411 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>410 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 411 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
412 ······</cpe-lang:logical-test>412 ······</cpe-lang:logical-test>
413 ····</cpe-lang:platform>413 ····</cpe-lang:platform>
414 ····<cpe-lang:platform·id="not_s390x_arch">414 ····<cpe-lang:platform·id="not_s390x_arch">
415 ······<cpe-lang:logical-test·operator="AND"·negate="false">415 ······<cpe-lang:logical-test·operator="AND"·negate="false">
416 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>416 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
417 ······</cpe-lang:logical-test>417 ······</cpe-lang:logical-test>
418 ····</cpe-lang:platform>418 ····</cpe-lang:platform>
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-fedora-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-fedora-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">28 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:39">
29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Fedora·39</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">32 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:40">
33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Fedora·40</cpe-dict:title>
Offset 51, 15 lines modifiedOffset 51, 15 lines modified
51 ······</cpe-dict:cpe-item>51 ······</cpe-dict:cpe-item>
52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">52 ······<cpe-dict:cpe-item·name="cpe:/o:fedoraproject:fedora:45">
53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>53 ········<cpe-dict:title·xml:lang="en-us">Fedora·45</cpe-dict:title>
54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>54 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-fedora-cpe-oval.xml">oval:ssg-installed_OS_is_fedora:def:1</cpe-dict:check>
55 ······</cpe-dict:cpe-item>55 ······</cpe-dict:cpe-item>
56 ····</cpe-dict:cpe-list>56 ····</cpe-dict:cpe-list>
57 ··</ds:component>57 ··</ds:component>
58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-02-28T20:08:00">58 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-xccdf.xml"·timestamp="2025-03-01T22:08:00">
59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">59 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FEDORA"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>60 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>61 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Fedora</xccdf-1.2:title>
62 ······<xccdf-1.2:description>62 ······<xccdf-1.2:description>
63 ········This·guide·presents·a·catalog·of·security-relevant63 ········This·guide·presents·a·catalog·of·security-relevant
64 configuration·settings·for·Fedora.·It·is·a·rendering·of64 configuration·settings·for·Fedora.·It·is·a·rendering·of
65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)65 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 224264, 15 lines modifiedOffset 224264, 15 lines modified
224264 ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>224264 ··············<xccdf-1.2:check-content-ref·href="ssg-fedora-ocil.xml"·name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
224265 ············</xccdf-1.2:check>224265 ············</xccdf-1.2:check>
224266 ··········</xccdf-1.2:Rule>224266 ··········</xccdf-1.2:Rule>
224267 ········</xccdf-1.2:Group>224267 ········</xccdf-1.2:Group>
224268 ······</xccdf-1.2:Group>224268 ······</xccdf-1.2:Group>
224269 ····</xccdf-1.2:Benchmark>224269 ····</xccdf-1.2:Benchmark>
224270 ··</ds:component>224270 ··</ds:component>
224271 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-02-28T20:08:00">224271 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-oval.xml"·timestamp="2025-03-01T22:08:00">
224272 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">224272 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
224273 ······<oval-def:generator>224273 ······<oval-def:generator>
224274 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>224274 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
224275 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>224275 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
224276 ········<oval:schema_version>5.11</oval:schema_version>224276 ········<oval:schema_version>5.11</oval:schema_version>
224277 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>224277 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
224278 ······</oval-def:generator>224278 ······</oval-def:generator>
Offset 273035, 8037 lines modifiedOffset 273035, 8037 lines modified
273035 ············</oval-def:arithmetic>273035 ············</oval-def:arithmetic>
273036 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>273036 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
273037 ··········</oval-def:arithmetic>273037 ··········</oval-def:arithmetic>
273038 ········</oval-def:local_variable>273038 ········</oval-def:local_variable>
273039 ······</oval-def:variables>273039 ······</oval-def:variables>
273040 ····</oval-def:oval_definitions>273040 ····</oval-def:oval_definitions>
273041 ··</ds:component>273041 ··</ds:component>
273042 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-02-28T20:08:00">273042 ··<ds:component·id="scap_org.open-scap_comp_ssg-fedora-ocil.xml"·timestamp="2025-03-01T22:08:00">
273043 ····<ocil:ocil>273043 ····<ocil:ocil>
273044 ······<ocil:generator>273044 ······<ocil:generator>
273045 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>273045 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
273046 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>273046 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
273047 ········<ocil:schema_version>2.0</ocil:schema_version>273047 ········<ocil:schema_version>2.0</ocil:schema_version>
273048 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>273048 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
273049 ······</ocil:generator>273049 ······</ocil:generator>
273050 ······<ocil:questionnaires>273050 ······<ocil:questionnaires>
273051 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"> 
273052 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title> 
273053 ··········<ocil:actions> 
273054 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref> 
273055 ··········</ocil:actions> 
273056 ········</ocil:questionnaire> 
273057 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1"> 
273058 ··········<ocil:title>Enable·module·signature·verification</ocil:title> 
273059 ··········<ocil:actions> 
273060 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref> 
273061 ··········</ocil:actions> 
273062 ········</ocil:questionnaire> 
273063 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">273051 ········<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
273064 ··········<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>273052 ··········<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
273065 ··········<ocil:actions>273053 ··········<ocil:actions>
273066 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>273054 ············<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
273067 ··········</ocil:actions>273055 ··········</ocil:actions>
273068 ········</ocil:questionnaire>273056 ········</ocil:questionnaire>
273069 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_slab_freelist_hardened_ocil:questionnaire:1">273057 ········<ocil:questionnaire·id="ocil:ssg-service_sssd_enabled_ocil:questionnaire:1">
273070 ··········<ocil:title>Harden·slab·freelist·metadata</ocil:title>273058 ··········<ocil:title>Enable·the·SSSD·Service</ocil:title>
273071 ··········<ocil:actions>273059 ··········<ocil:actions>
273072 ············<ocil:test_action_ref>ocil:ssg-kernel_config_slab_freelist_hardened_action:testaction:1</ocil:test_action_ref>273060 ············<ocil:test_action_ref>ocil:ssg-service_sssd_enabled_action:testaction:1</ocil:test_action_ref>
273073 ··········</ocil:actions>273061 ··········</ocil:actions>
273074 ········</ocil:questionnaire>273062 ········</ocil:questionnaire>
273075 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> 
273076 ··········<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>273063 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1">
 273064 ··········<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·open·Are·Ordered·Correctly</ocil:title>
273077 ··········<ocil:actions>273065 ··········<ocil:actions>
273078 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>273066 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_action:testaction:1</ocil:test_action_ref>
273079 ··········</ocil:actions>273067 ··········</ocil:actions>
273080 ········</ocil:questionnaire>273068 ········</ocil:questionnaire>
273081 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">273069 ········<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">
273082 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>273070 ··········<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>
273083 ··········<ocil:actions>273071 ··········<ocil:actions>
273084 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>273072 ············<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>
273085 ··········</ocil:actions>273073 ··········</ocil:actions>
273086 ········</ocil:questionnaire>273074 ········</ocil:questionnaire>
273087 ········<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">273075 ········<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
273088 ··········<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>273076 ··········<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
273089 ··········<ocil:actions>273077 ··········<ocil:actions>
273090 ············<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>273078 ············<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
273091 ··········</ocil:actions>273079 ··········</ocil:actions>
273092 ········</ocil:questionnaire>273080 ········</ocil:questionnaire>
273093 ········<ocil:questionnaire·id="ocil:ssg-clean_components_post_updating_ocil:questionnaire:1">273081 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1">
273094 ··········<ocil:title>Ensure·dnf·Removes·Previous·Package·Versions</ocil:title>273082 ··········<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>
273095 ··········<ocil:actions>273083 ··········<ocil:actions>
273096 ············<ocil:test_action_ref>ocil:ssg-clean_components_post_updating_action:testaction:1</ocil:test_action_ref>273084 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
273097 ··········</ocil:actions>273085 ··········</ocil:actions>
273098 ········</ocil:questionnaire>273086 ········</ocil:questionnaire>
273099 ········<ocil:questionnaire·id="ocil:ssg-package_sssd-ipa_installed_ocil:questionnaire:1">273087 ········<ocil:questionnaire·id="ocil:ssg-sssd_enable_smartcards_ocil:questionnaire:1">
273100 ··········<ocil:title>Install·sssd-ipa·Package</ocil:title>273088 ··········<ocil:title>Enable·Smartcards·in·SSSD</ocil:title>
273101 ··········<ocil:actions>273089 ··········<ocil:actions>
273102 ············<ocil:test_action_ref>ocil:ssg-package_sssd-ipa_installed_action:testaction:1</ocil:test_action_ref>273090 ············<ocil:test_action_ref>ocil:ssg-sssd_enable_smartcards_action:testaction:1</ocil:test_action_ref>
273103 ··········</ocil:actions>273091 ··········</ocil:actions>
273104 ········</ocil:questionnaire>273092 ········</ocil:questionnaire>
273105 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1">273093 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
273106 ··········<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>273094 ··········<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>
273107 ··········<ocil:actions>273095 ··········<ocil:actions>
273108 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>273096 ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
273109 ··········</ocil:actions>273097 ··········</ocil:actions>
273110 ········</ocil:questionnaire>273098 ········</ocil:questionnaire>
273111 ········<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1">273099 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
273112 ··········<ocil:title>Install·firewalld·Package</ocil:title>273100 ··········<ocil:title>Enable·Yama·support</ocil:title>
Max diff block lines reached; 2141098/2152339 bytes (99.48%) of diff not shown.
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
Ordering differences only
    
Offset 3, 8028 lines modifiedOffset 3, 8028 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1"> 
17 ······<ocil:title>Enable·module·signature·verification</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>11 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_slab_freelist_hardened_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-service_sssd_enabled_ocil:questionnaire:1">
29 ······<ocil:title>Harden·slab·freelist·metadata</ocil:title>17 ······<ocil:title>Enable·the·SSSD·Service</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_slab_freelist_hardened_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_sssd_enabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1">
 23 ······<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·open·Are·Ordered·Correctly</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-group_unique_id_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>29 ······<ocil:title>Ensure·All·Groups·on·the·System·Have·Unique·Group·ID</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Core·Dumps·for·All·Users</ocil:title>35 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-clean_components_post_updating_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·dnf·Removes·Previous·Package·Versions</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-clean_components_post_updating_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-package_sssd-ipa_installed_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sssd_enable_smartcards_ocil:questionnaire:1">
59 ······<ocil:title>Install·sssd-ipa·Package</ocil:title>47 ······<ocil:title>Enable·Smartcards·in·SSSD</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-package_sssd-ipa_installed_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sssd_enable_smartcards_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>53 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
71 ······<ocil:title>Install·firewalld·Package</ocil:title>59 ······<ocil:title>Enable·Yama·support</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_gcc_plugin_structleak_byref_all_ocil:questionnaire:1"> 
77 ······<ocil:title>zero-init·everything·passed·by·reference</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
 65 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_structleak_byref_all_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-network_sniffer_disabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-aide_check_audit_tools_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·System·is·Not·Acting·as·a·Network·Sniffer</ocil:title>71 ······<ocil:title>Configure·AIDE·to·Verify·the·Audit·Tools</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-network_sniffer_disabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-aide_check_audit_tools_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nodev_ocil:questionnaire:1"> 
89 ······<ocil:title>Add·nodev·Option·to·/var/log/audit</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_ocil:questionnaire:1">
 77 ······<ocil:title>Record·Successful·Creation·Attempts·to·Files·-·open_by_handle_at·O_CREAT</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nodev_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1"> 
95 ······<ocil:title>Limit·Password·Reuse</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Owner·on·cron.daily</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_root_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-grub2_page_poison_argument_ocil:questionnaire:1">
101 ······<ocil:title>Configure·the·root·Account·for·Failed·Password·Attempts</ocil:title>89 ······<ocil:title>Enable·page·allocator·poisoning</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_root_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_page_poison_argument_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_encrypt_sent_records_ocil:questionnaire:1"> 
107 ······<ocil:title>Encrypt·Audit·Records·Sent·With·audispd·Plugin</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_grub2_cfg_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·Group·Ownership</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_encrypt_sent_records_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_automatic_login_ocil:questionnaire:1">
113 ······<ocil:title>Configure·Auto·Configuration·on·All·IPv6·Interfaces</ocil:title>101 ······<ocil:title>Disable·GDM·Automatic·Login</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_automatic_login_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_vsyscall_emulate_ocil:questionnaire:1">
119 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>107 ······<ocil:title>Disable·vsyscall·emulation</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_vsyscall_emulate_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
123 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
Max diff block lines reached; 2047843/2060132 bytes (99.40%) of diff not shown.
241 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
241 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 20889, 15 lines modifiedOffset 20889, 15 lines modified
20889 ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/>20889 ··············<xccdf-1.2:check-content-ref·href="ssg-kylinserver10-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/>
20890 ············</xccdf-1.2:check>20890 ············</xccdf-1.2:check>
20891 ··········</xccdf-1.2:Rule>20891 ··········</xccdf-1.2:Rule>
20892 ········</xccdf-1.2:Group>20892 ········</xccdf-1.2:Group>
20893 ······</xccdf-1.2:Group>20893 ······</xccdf-1.2:Group>
20894 ····</xccdf-1.2:Benchmark>20894 ····</xccdf-1.2:Benchmark>
20895 ··</ds:component>20895 ··</ds:component>
20896 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-02-28T20:08:00">20896 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"·timestamp="2025-03-01T22:08:00">
20897 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">20897 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
20898 ······<oval-def:generator>20898 ······<oval-def:generator>
20899 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>20899 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
20900 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>20900 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
20901 ········<oval:schema_version>5.11</oval:schema_version>20901 ········<oval:schema_version>5.11</oval:schema_version>
20902 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>20902 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
20903 ······</oval-def:generator>20903 ······</oval-def:generator>
Offset 26495, 758 lines modifiedOffset 26495, 758 lines modified
26495 ············</oval-def:arithmetic>26495 ············</oval-def:arithmetic>
26496 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>26496 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
26497 ··········</oval-def:arithmetic>26497 ··········</oval-def:arithmetic>
26498 ········</oval-def:local_variable>26498 ········</oval-def:local_variable>
26499 ······</oval-def:variables>26499 ······</oval-def:variables>
26500 ····</oval-def:oval_definitions>26500 ····</oval-def:oval_definitions>
26501 ··</ds:component>26501 ··</ds:component>
26502 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-02-28T20:08:00">26502 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"·timestamp="2025-03-01T22:08:00">
26503 ····<ocil:ocil>26503 ····<ocil:ocil>
26504 ······<ocil:generator>26504 ······<ocil:generator>
26505 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>26505 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
26506 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>26506 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
26507 ········<ocil:schema_version>2.0</ocil:schema_version>26507 ········<ocil:schema_version>2.0</ocil:schema_version>
26508 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>26508 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
26509 ······</ocil:generator>26509 ······</ocil:generator>
26510 ······<ocil:questionnaires>26510 ······<ocil:questionnaires>
26511 ········<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">26511 ········<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
26512 ··········<ocil:title>Modify·the·System·Login·Banner</ocil:title>26512 ··········<ocil:title>Disable·the·Automounter</ocil:title>
26513 ··········<ocil:actions>26513 ··········<ocil:actions>
26514 ············<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>26514 ············<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
26515 ··········</ocil:actions>26515 ··········</ocil:actions>
26516 ········</ocil:questionnaire>26516 ········</ocil:questionnaire>
26517 ········<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">26517 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_cron_logging_ocil:questionnaire:1">
26518 ··········<ocil:title>Uninstall·rsync·Package</ocil:title>26518 ··········<ocil:title>Ensure·cron·Is·Logging·To·Rsyslog</ocil:title>
26519 ··········<ocil:actions>26519 ··········<ocil:actions>
26520 ············<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>26520 ············<ocil:test_action_ref>ocil:ssg-rsyslog_cron_logging_action:testaction:1</ocil:test_action_ref>
26521 ··········</ocil:actions>26521 ··········</ocil:actions>
26522 ········</ocil:questionnaire>26522 ········</ocil:questionnaire>
26523 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">26523 ········<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">
26524 ··········<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>26524 ··········<ocil:title>Uninstall·rsync·Package</ocil:title>
26525 ··········<ocil:actions>26525 ··········<ocil:actions>
26526 ············<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>26526 ············<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>
26527 ··········</ocil:actions>26527 ··········</ocil:actions>
26528 ········</ocil:questionnaire>26528 ········</ocil:questionnaire>
26529 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"> 
26530 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>26529 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
 26530 ··········<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
26531 ··········<ocil:actions>26531 ··········<ocil:actions>
26532 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>26532 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
26533 ··········</ocil:actions>26533 ··········</ocil:actions>
26534 ········</ocil:questionnaire>26534 ········</ocil:questionnaire>
26535 ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">26535 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
26536 ··········<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>26536 ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title>
26537 ··········<ocil:actions>26537 ··········<ocil:actions>
26538 ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>26538 ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
26539 ··········</ocil:actions>26539 ··········</ocil:actions>
26540 ········</ocil:questionnaire>26540 ········</ocil:questionnaire>
26541 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1"> 
26542 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>26541 ········<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">
 26542 ··········<ocil:title>Enable·rsyslog·Service</ocil:title>
26543 ··········<ocil:actions>26543 ··········<ocil:actions>
26544 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>26544 ············<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>
26545 ··········</ocil:actions>26545 ··········</ocil:actions>
26546 ········</ocil:questionnaire>26546 ········</ocil:questionnaire>
26547 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1"> 
26548 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>26547 ········<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">
 26548 ··········<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>
26549 ··········<ocil:actions>26549 ··········<ocil:actions>
26550 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>26550 ············<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>
26551 ··········</ocil:actions>26551 ··········</ocil:actions>
26552 ········</ocil:questionnaire>26552 ········</ocil:questionnaire>
26553 ········<ocil:questionnaire·id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1">26553 ········<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">
26554 ··········<ocil:title>The·operating·system·must·restrict·privilege·elevation·to·authorized·personnel</ocil:title>26554 ··········<ocil:title>Enable·the·OpenSSH·Service</ocil:title>
26555 ··········<ocil:actions>26555 ··········<ocil:actions>
26556 ············<ocil:test_action_ref>ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1</ocil:test_action_ref>26556 ············<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>
26557 ··········</ocil:actions>26557 ··········</ocil:actions>
26558 ········</ocil:questionnaire>26558 ········</ocil:questionnaire>
26559 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">26559 ········<ocil:questionnaire·id="ocil:ssg-package_nfs-utils_removed_ocil:questionnaire:1">
26560 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>26560 ··········<ocil:title>Uninstall·nfs-utils·Package</ocil:title>
26561 ··········<ocil:actions>26561 ··········<ocil:actions>
26562 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>26562 ············<ocil:test_action_ref>ocil:ssg-package_nfs-utils_removed_action:testaction:1</ocil:test_action_ref>
26563 ··········</ocil:actions>26563 ··········</ocil:actions>
26564 ········</ocil:questionnaire>26564 ········</ocil:questionnaire>
26565 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">26565 ········<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1">
26566 ··········<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>26566 ··········<ocil:title>Ensure·gpgcheck·Enabled·for·All·dnf·Package·Repositories</ocil:title>
26567 ··········<ocil:actions>26567 ··········<ocil:actions>
26568 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>26568 ············<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1</ocil:test_action_ref>
26569 ··········</ocil:actions>26569 ··········</ocil:actions>
26570 ········</ocil:questionnaire>26570 ········</ocil:questionnaire>
Max diff block lines reached; 234521/246254 bytes (95.24%) of diff not shown.
225 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
225 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
Ordering differences only
    
Offset 3, 749 lines modifiedOffset 3, 749 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
11 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title>11 ······<ocil:title>Disable·the·Automounter</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_cron_logging_ocil:questionnaire:1">
17 ······<ocil:title>Uninstall·rsync·Package</ocil:title>17 ······<ocil:title>Ensure·cron·Is·Logging·To·Rsyslog</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-rsyslog_cron_logging_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·System·Log·Files·Have·Correct·Permissions</ocil:title>23 ······<ocil:title>Uninstall·rsync·Package</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"> 
29 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
35 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>35 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">
 41 ······<ocil:title>Enable·rsyslog·Service</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Enforce·for·root·User</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1"> 
53 ······<ocil:title>The·operating·system·must·restrict·privilege·elevation·to·authorized·personnel</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_nfs-utils_removed_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>59 ······<ocil:title>Uninstall·nfs-utils·Package</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_nfs-utils_removed_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>65 ······<ocil:title>Ensure·gpgcheck·Enabled·for·All·dnf·Package·Repositories</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
71 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>71 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">
77 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>77 ······<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">
83 ······<ocil:title>Install·the·ntp·service</ocil:title>83 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Authentication·Retry·Prompts·Permitted·Per-Session</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
89 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>89 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_motd_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
95 ······<ocil:title>Modify·the·System·Message·of·the·Day·Banner</ocil:title>95 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-banner_etc_motd_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_tftp_removed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
101 ······<ocil:title>Remove·tftp·Daemon</ocil:title>101 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_tftp_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1">
107 ······<ocil:title>Limit·Password·Reuse</ocil:title>107 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">
113 ······<ocil:title>Install·AIDE</ocil:title>113 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_cron_logging_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·cron·Is·Logging·To·Rsyslog</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 119 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-rsyslog_cron_logging_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1"> 
Max diff block lines reached; 218158/230404 bytes (94.68%) of diff not shown.
9.12 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
9.02 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">
29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 563, 15 lines modifiedOffset 563, 15 lines modified
563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>
564 ············</xccdf-1.2:check>564 ············</xccdf-1.2:check>
565 ··········</xccdf-1.2:Rule>565 ··········</xccdf-1.2:Rule>
566 ········</xccdf-1.2:Group>566 ········</xccdf-1.2:Group>
567 ······</xccdf-1.2:Group>567 ······</xccdf-1.2:Group>
568 ····</xccdf-1.2:Benchmark>568 ····</xccdf-1.2:Benchmark>
569 ··</ds:component>569 ··</ds:component>
570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-02-28T20:08:00">570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-03-01T22:08:00">
571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
572 ······<oval-def:generator>572 ······<oval-def:generator>
573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
575 ········<oval:schema_version>5.11</oval:schema_version>575 ········<oval:schema_version>5.11</oval:schema_version>
576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
577 ······</oval-def:generator>577 ······</oval-def:generator>
Offset 600, 74 lines modifiedOffset 600, 74 lines modified
600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>
601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>
602 ··········<ind:instance·datatype="int">1</ind:instance>602 ··········<ind:instance·datatype="int">1</ind:instance>
603 ········</ind:textfilecontent54_object>603 ········</ind:textfilecontent54_object>
604 ······</oval-def:objects>604 ······</oval-def:objects>
605 ····</oval-def:oval_definitions>605 ····</oval-def:oval_definitions>
606 ··</ds:component>606 ··</ds:component>
607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-02-28T20:08:00">607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-03-01T22:08:00">
608 ····<ocil:ocil>608 ····<ocil:ocil>
609 ······<ocil:generator>609 ······<ocil:generator>
610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
612 ········<ocil:schema_version>2.0</ocil:schema_version>612 ········<ocil:schema_version>2.0</ocil:schema_version>
613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
614 ······</ocil:generator>614 ······</ocil:generator>
615 ······<ocil:questionnaires>615 ······<ocil:questionnaires>
616 ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> 
617 ··········<ocil:title>Enable·audit·Service</ocil:title> 
618 ··········<ocil:actions> 
619 ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> 
620 ··········</ocil:actions> 
621 ········</ocil:questionnaire> 
622 ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">616 ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">
623 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>617 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>
624 ··········<ocil:actions>618 ··········<ocil:actions>
625 ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>619 ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>
626 ··········</ocil:actions>620 ··········</ocil:actions>
627 ········</ocil:questionnaire>621 ········</ocil:questionnaire>
 622 ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1">
 623 ··········<ocil:title>Enable·audit·Service</ocil:title>
 624 ··········<ocil:actions>
 625 ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref>
 626 ··········</ocil:actions>
 627 ········</ocil:questionnaire>
628 ······</ocil:questionnaires>628 ······</ocil:questionnaires>
629 ······<ocil:test_actions>629 ······<ocil:test_actions>
630 ········<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">630 ········<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">
631 ··········<ocil:when_true>631 ··········<ocil:when_true>
632 ············<ocil:result>PASS</ocil:result>632 ············<ocil:result>PASS</ocil:result>
633 ··········</ocil:when_true>633 ··········</ocil:when_true>
634 ··········<ocil:when_false>634 ··········<ocil:when_false>
635 ············<ocil:result>FAIL</ocil:result>635 ············<ocil:result>FAIL</ocil:result>
636 ··········</ocil:when_false>636 ··········</ocil:when_false>
637 ········</ocil:boolean_question_test_action>637 ········</ocil:boolean_question_test_action>
638 ········<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">638 ········<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
639 ··········<ocil:when_true>639 ··········<ocil:when_true>
640 ············<ocil:result>PASS</ocil:result>640 ············<ocil:result>PASS</ocil:result>
641 ··········</ocil:when_true>641 ··········</ocil:when_true>
642 ··········<ocil:when_false>642 ··········<ocil:when_false>
643 ············<ocil:result>FAIL</ocil:result>643 ············<ocil:result>FAIL</ocil:result>
644 ··········</ocil:when_false>644 ··········</ocil:when_false>
645 ········</ocil:boolean_question_test_action>645 ········</ocil:boolean_question_test_action>
646 ······</ocil:test_actions>646 ······</ocil:test_actions>
647 ······<ocil:questions>647 ······<ocil:questions>
 648 ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1">
 649 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
 650 following·command:
 651 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
 652 The·output·should·contain·ahlt
 653 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
 654 ········</ocil:boolean_question>
648 ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">655 ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
649 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the656 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
650 following·command:657 following·command:
651 $·sudo·launchctl·list·com.apple.auditd658 $·sudo·launchctl·list·com.apple.auditd
652 The·output·should·return·process·information·for659 The·output·should·return·process·information·for
653 com.apple.auditd660 com.apple.auditd
654 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>661 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>
655 ········</ocil:boolean_question>662 ········</ocil:boolean_question>
656 ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> 
657 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the 
658 following·command: 
659 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control 
660 The·output·should·contain·ahlt 
661 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> 
662 ········</ocil:boolean_question> 
663 ······</ocil:questions>663 ······</ocil:questions>
664 ····</ocil:ocil>664 ····</ocil:ocil>
665 ··</ds:component>665 ··</ds:component>
666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-02-28T20:08:00">666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-03-01T22:08:00">
667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
668 ······<oval-def:generator>668 ······<oval-def:generator>
669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>
670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
671 ········<oval:schema_version>5.11</oval:schema_version>671 ········<oval:schema_version>5.11</oval:schema_version>
672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
673 ······</oval-def:generator>673 ······</oval-def:generator>
Max diff block lines reached; -1/9126 bytes (-0.01%) of diff not shown.
4.0 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ocil.xml
3.89 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ocil.xml
Ordering differences only
    
Offset 3, 56 lines modifiedOffset 3, 56 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·audit·Service</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">
17 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>11 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
 16 ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1">
 17 ······<ocil:title>Enable·audit·Service</ocil:title>
 18 ······<ocil:actions>
 19 ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref>
 20 ······</ocil:actions>
 21 ····</ocil:questionnaire>
22 ··</ocil:questionnaires>22 ··</ocil:questionnaires>
23 ··<ocil:test_actions>23 ··<ocil:test_actions>
24 ····<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">24 ····<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">
25 ······<ocil:when_true>25 ······<ocil:when_true>
26 ········<ocil:result>PASS</ocil:result>26 ········<ocil:result>PASS</ocil:result>
27 ······</ocil:when_true>27 ······</ocil:when_true>
28 ······<ocil:when_false>28 ······<ocil:when_false>
29 ········<ocil:result>FAIL</ocil:result>29 ········<ocil:result>FAIL</ocil:result>
30 ······</ocil:when_false>30 ······</ocil:when_false>
31 ····</ocil:boolean_question_test_action>31 ····</ocil:boolean_question_test_action>
32 ····<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">32 ····<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
33 ······<ocil:when_true>33 ······<ocil:when_true>
34 ········<ocil:result>PASS</ocil:result>34 ········<ocil:result>PASS</ocil:result>
35 ······</ocil:when_true>35 ······</ocil:when_true>
36 ······<ocil:when_false>36 ······<ocil:when_false>
37 ········<ocil:result>FAIL</ocil:result>37 ········<ocil:result>FAIL</ocil:result>
38 ······</ocil:when_false>38 ······</ocil:when_false>
39 ····</ocil:boolean_question_test_action>39 ····</ocil:boolean_question_test_action>
40 ··</ocil:test_actions>40 ··</ocil:test_actions>
41 ··<ocil:questions>41 ··<ocil:questions>
 42 ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1">
 43 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
 44 following·command:
 45 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
 46 The·output·should·contain·ahlt
 47 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
 48 ····</ocil:boolean_question>
42 ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">49 ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
43 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the50 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
44 following·command:51 following·command:
45 $·sudo·launchctl·list·com.apple.auditd52 $·sudo·launchctl·list·com.apple.auditd
46 The·output·should·return·process·information·for53 The·output·should·return·process·information·for
47 com.apple.auditd54 com.apple.auditd
48 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>55 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>
49 ····</ocil:boolean_question>56 ····</ocil:boolean_question>
50 ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> 
51 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the 
52 following·command: 
53 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control 
54 The·output·should·contain·ahlt 
55 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> 
56 ····</ocil:boolean_question> 
57 ··</ocil:questions>57 ··</ocil:questions>
58 </ocil:ocil>58 </ocil:ocil>
877 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
877 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>
Offset 111, 15 lines modifiedOffset 111, 15 lines modified
111 ······</cpe-dict:cpe-item>111 ······</cpe-dict:cpe-item>
112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">
113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>
114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>
115 ······</cpe-dict:cpe-item>115 ······</cpe-dict:cpe-item>
116 ····</cpe-dict:cpe-list>116 ····</cpe-dict:cpe-list>
117 ··</ds:component>117 ··</ds:component>
118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-02-28T20:08:00">118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>120 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>
122 ······<xccdf-1.2:description>122 ······<xccdf-1.2:description>
123 ········This·guide·presents·a·catalog·of·security-relevant123 ········This·guide·presents·a·catalog·of·security-relevant
124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of
125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 22582, 15 lines modifiedOffset 22582, 15 lines modified
22582 ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/>22582 ··············<xccdf-1.2:check-content-ref·href="ssg-ocp4-ocil.xml"·name="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1"/>
22583 ············</xccdf-1.2:check>22583 ············</xccdf-1.2:check>
22584 ··········</xccdf-1.2:Rule>22584 ··········</xccdf-1.2:Rule>
22585 ········</xccdf-1.2:Group>22585 ········</xccdf-1.2:Group>
22586 ······</xccdf-1.2:Group>22586 ······</xccdf-1.2:Group>
22587 ····</xccdf-1.2:Benchmark>22587 ····</xccdf-1.2:Benchmark>
22588 ··</ds:component>22588 ··</ds:component>
22589 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-02-28T20:08:00">22589 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-oval.xml"·timestamp="2025-03-01T22:08:00">
22590 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">22590 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
22591 ······<oval-def:generator>22591 ······<oval-def:generator>
22592 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>22592 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
22593 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>22593 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
22594 ········<oval:schema_version>5.11</oval:schema_version>22594 ········<oval:schema_version>5.11</oval:schema_version>
22595 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>22595 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
22596 ······</oval-def:generator>22596 ······</oval-def:generator>
Offset 34382, 4502 lines modifiedOffset 34382, 4502 lines modified
34382 ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/>34382 ············<oval-def:variable_component·var_ref="oval:ssg-ocp_data_root:var:1"/>
34383 ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component>34383 ············<oval-def:literal_component>/apis/apps/v1/namespaces/openshift-ingress/deployments/router-default#aa685c2fe85cfde2ec878952fdd5e72b0824bdaccd1063efcfc29fea8137840c</oval-def:literal_component>
34384 ··········</oval-def:concat>34384 ··········</oval-def:concat>
34385 ········</oval-def:local_variable>34385 ········</oval-def:local_variable>
34386 ······</oval-def:variables>34386 ······</oval-def:variables>
34387 ····</oval-def:oval_definitions>34387 ····</oval-def:oval_definitions>
34388 ··</ds:component>34388 ··</ds:component>
34389 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-02-28T20:08:00">34389 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-ocil.xml"·timestamp="2025-03-01T22:08:00">
34390 ····<ocil:ocil>34390 ····<ocil:ocil>
34391 ······<ocil:generator>34391 ······<ocil:generator>
34392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>34392 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
34393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>34393 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
34394 ········<ocil:schema_version>2.0</ocil:schema_version>34394 ········<ocil:schema_version>2.0</ocil:schema_version>
34395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>34395 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
34396 ······</ocil:generator>34396 ······</ocil:generator>
34397 ······<ocil:questionnaires>34397 ······<ocil:questionnaires>
34398 ········<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_kube_audit_ocil:questionnaire:1"> 
34399 ··········<ocil:title>The·Kubernetes·Audit·Logs·Directory·Must·Have·Mode·0700</ocil:title> 
34400 ··········<ocil:actions> 
34401 ············<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_kube_audit_action:testaction:1</ocil:test_action_ref> 
34402 ··········</ocil:actions> 
34403 ········</ocil:questionnaire> 
34404 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_ca_ocil:questionnaire:1">34398 ········<ocil:questionnaire·id="ocil:ssg-scc_limit_privileged_containers_ocil:questionnaire:1">
34405 ··········<ocil:title>Verify·Permissions·on·the·Worker·Certificate·Authority·File</ocil:title>34399 ··········<ocil:title>Limit·Privileged·Container·Use</ocil:title>
34406 ··········<ocil:actions>34400 ··········<ocil:actions>
34407 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_ca_action:testaction:1</ocil:test_action_ref>34401 ············<ocil:test_action_ref>ocil:ssg-scc_limit_privileged_containers_action:testaction:1</ocil:test_action_ref>
34408 ··········</ocil:actions>34402 ··········</ocil:actions>
34409 ········</ocil:questionnaire>34403 ········</ocil:questionnaire>
34410 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_openshift_pki_cert_files_ocil:questionnaire:1">34404 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_conf_db_lock_s390x_ocil:questionnaire:1">
34411 ··········<ocil:title>Verify·Group·Who·Owns·The·OpenShift·PKI·Certificate·Files</ocil:title>34405 ··········<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Configuration·Database·Lock</ocil:title>
34412 ··········<ocil:actions>34406 ··········<ocil:actions>
34413 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_openshift_pki_cert_files_action:testaction:1</ocil:test_action_ref>34407 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_conf_db_lock_s390x_action:testaction:1</ocil:test_action_ref>
34414 ··········</ocil:actions>34408 ··········</ocil:actions>
34415 ········</ocil:questionnaire>34409 ········</ocil:questionnaire>
34416 ········<ocil:questionnaire·id="ocil:ssg-file_owner_kubeconfig_ocil:questionnaire:1">34410 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_openshift_apiserver_ocil:questionnaire:1">
34417 ··········<ocil:title>Verify·User·Who·Owns·The·OpenShift·Admin·Kubeconfig·File</ocil:title>34411 ··········<ocil:title>Ensure·/var/log/openshift-apiserver·Located·On·Separate·Partition</ocil:title>
34418 ··········<ocil:actions>34412 ··········<ocil:actions>
34419 ············<ocil:test_action_ref>ocil:ssg-file_owner_kubeconfig_action:testaction:1</ocil:test_action_ref>34413 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_openshift_apiserver_action:testaction:1</ocil:test_action_ref>
34420 ··········</ocil:actions>34414 ··········</ocil:actions>
34421 ········</ocil:questionnaire>34415 ········</ocil:questionnaire>
34422 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubeconfig_ocil:questionnaire:1">34416 ········<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">
34423 ··········<ocil:title>Verify·Group·Who·Owns·The·OpenShift·Admin·Kubeconfig·File</ocil:title>34417 ··········<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>
34424 ··········<ocil:actions>34418 ··········<ocil:actions>
34425 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubeconfig_action:testaction:1</ocil:test_action_ref>34419 ············<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>
34426 ··········</ocil:actions>34420 ··········</ocil:actions>
34427 ········</ocil:questionnaire>34421 ········</ocil:questionnaire>
34428 ········<ocil:questionnaire·id="ocil:ssg-scc_limit_net_raw_capability_ocil:questionnaire:1"> 
34429 ··········<ocil:title>Limit·Use·of·the·CAP_NET_RAW</ocil:title>34422 ········<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_ocil:questionnaire:1">
 34423 ··········<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionHard:·memory.available</ocil:title>
34430 ··········<ocil:actions>34424 ··········<ocil:actions>
34431 ············<ocil:test_action_ref>ocil:ssg-scc_limit_net_raw_capability_action:testaction:1</ocil:test_action_ref>34425 ············<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_action:testaction:1</ocil:test_action_ref>
34432 ··········</ocil:actions>34426 ··········</ocil:actions>
34433 ········</ocil:questionnaire>34427 ········</ocil:questionnaire>
34434 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">34428 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
34435 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>34429 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
34436 ··········<ocil:actions>34430 ··········<ocil:actions>
34437 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>34431 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
34438 ··········</ocil:actions>34432 ··········</ocil:actions>
34439 ········</ocil:questionnaire>34433 ········</ocil:questionnaire>
34440 ········<ocil:questionnaire·id="ocil:ssg-audit_log_forwarding_webhook_ocil:questionnaire:1">34434 ········<ocil:questionnaire·id="ocil:ssg-file_owner_worker_ca_ocil:questionnaire:1">
34441 ··········<ocil:title>Ensure·that·Audit·Log·Webhook·Is·Configured</ocil:title>34435 ··········<ocil:title>Verify·User·Who·Owns·the·Worker·Certificate·Authority·File</ocil:title>
34442 ··········<ocil:actions>34436 ··········<ocil:actions>
34443 ············<ocil:test_action_ref>ocil:ssg-audit_log_forwarding_webhook_action:testaction:1</ocil:test_action_ref>34437 ············<ocil:test_action_ref>ocil:ssg-file_owner_worker_ca_action:testaction:1</ocil:test_action_ref>
34444 ··········</ocil:actions>34438 ··········</ocil:actions>
34445 ········</ocil:questionnaire>34439 ········</ocil:questionnaire>
34446 ········<ocil:questionnaire·id="ocil:ssg-scheduler_port_is_zero_ocil:questionnaire:1">34440 ········<ocil:questionnaire·id="ocil:ssg-gitops_operator_exists_ocil:questionnaire:1">
34447 ··········<ocil:title>Ensure·that·the·port·parameter·is·zero</ocil:title>34441 ··········<ocil:title>Ensure·that·GitOps·Operator·is·deployed</ocil:title>
34448 ··········<ocil:actions>34442 ··········<ocil:actions>
34449 ············<ocil:test_action_ref>ocil:ssg-scheduler_port_is_zero_action:testaction:1</ocil:test_action_ref>34443 ············<ocil:test_action_ref>ocil:ssg-gitops_operator_exists_action:testaction:1</ocil:test_action_ref>
34450 ··········</ocil:actions>34444 ··········</ocil:actions>
34451 ········</ocil:questionnaire>34445 ········</ocil:questionnaire>
34452 ········<ocil:questionnaire·id="ocil:ssg-ocp_insecure_registries_ocil:questionnaire:1">34446 ········<ocil:questionnaire·id="ocil:ssg-etcd_unique_ca_ocil:questionnaire:1">
34453 ··········<ocil:title>Check·if·any·insecure·registry·sources·is·configured</ocil:title>34447 ··········<ocil:title>Configure·A·Unique·CA·Certificate·for·etcd</ocil:title>
34454 ··········<ocil:actions>34448 ··········<ocil:actions>
34455 ············<ocil:test_action_ref>ocil:ssg-ocp_insecure_registries_action:testaction:1</ocil:test_action_ref>34449 ············<ocil:test_action_ref>ocil:ssg-etcd_unique_ca_action:testaction:1</ocil:test_action_ref>
34456 ··········</ocil:actions>34450 ··········</ocil:actions>
34457 ········</ocil:questionnaire>34451 ········</ocil:questionnaire>
34458 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_vswitchd_pid_ocil:questionnaire:1">34452 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1">
34459 ··········<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Daemon·PID·File</ocil:title>34453 ··········<ocil:title>Verify·Permissions·on·the·OpenShift·Node·Service·File</ocil:title>
Max diff block lines reached; 885781/897835 bytes (98.66%) of diff not shown.
840 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
840 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
Ordering differences only
    
Offset 3, 4493 lines modifiedOffset 3, 4493 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_kube_audit_ocil:questionnaire:1"> 
11 ······<ocil:title>The·Kubernetes·Audit·Logs·Directory·Must·Have·Mode·0700</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_kube_audit_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_ca_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-scc_limit_privileged_containers_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Permissions·on·the·Worker·Certificate·Authority·File</ocil:title>11 ······<ocil:title>Limit·Privileged·Container·Use</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_ca_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-scc_limit_privileged_containers_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_openshift_pki_cert_files_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_conf_db_lock_s390x_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Group·Who·Owns·The·OpenShift·PKI·Certificate·Files</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Configuration·Database·Lock</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_openshift_pki_cert_files_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_conf_db_lock_s390x_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubeconfig_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·Admin·Kubeconfig·File</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_openshift_apiserver_ocil:questionnaire:1">
 23 ······<ocil:title>Ensure·/var/log/openshift-apiserver·Located·On·Separate·Partition</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubeconfig_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_openshift_apiserver_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubeconfig_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Group·Who·Owns·The·OpenShift·Admin·Kubeconfig·File</ocil:title>29 ······<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubeconfig_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-scc_limit_net_raw_capability_ocil:questionnaire:1"> 
41 ······<ocil:title>Limit·Use·of·the·CAP_NET_RAW</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_ocil:questionnaire:1">
 35 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionHard:·memory.available</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-scc_limit_net_raw_capability_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_hard_memory_available_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
47 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>41 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_log_forwarding_webhook_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_ca_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·that·Audit·Log·Webhook·Is·Configured</ocil:title>47 ······<ocil:title>Verify·User·Who·Owns·the·Worker·Certificate·Authority·File</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_log_forwarding_webhook_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_ca_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-scheduler_port_is_zero_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-gitops_operator_exists_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·that·the·port·parameter·is·zero</ocil:title>53 ······<ocil:title>Ensure·that·GitOps·Operator·is·deployed</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-scheduler_port_is_zero_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-gitops_operator_exists_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-ocp_insecure_registries_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-etcd_unique_ca_ocil:questionnaire:1">
65 ······<ocil:title>Check·if·any·insecure·registry·sources·is·configured</ocil:title>59 ······<ocil:title>Configure·A·Unique·CA·Certificate·for·etcd</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-ocp_insecure_registries_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-etcd_unique_ca_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_vswitchd_pid_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_service_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Daemon·PID·File</ocil:title>65 ······<ocil:title>Verify·Permissions·on·the·OpenShift·Node·Service·File</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_vswitchd_pid_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_service_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-general_namespaces_in_use_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-api_server_auth_mode_no_aa_ocil:questionnaire:1">
77 ······<ocil:title>Create·administrative·boundaries·between·resources·using·namespaces</ocil:title>71 ······<ocil:title>The·authorization-mode·cannot·be·AlwaysAllow</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-general_namespaces_in_use_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-api_server_auth_mode_no_aa_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_cert_pre_4_9_ocil:questionnaire:1">
83 ······<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title>77 ······<ocil:title>Ensure·That·The·kubelet·Client·Certificate·Is·Correctly·Set</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_cert_pre_4_9_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-liveness_readiness_probe_in_workload_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-ocp_allowed_registries_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·that·all·workloads·have·liveness·and·readiness·probes</ocil:title>83 ······<ocil:title>Allowed·registries·are·configured</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-liveness_readiness_probe_in_workload_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-ocp_allowed_registries_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-api_server_kubelet_client_cert_pre_4_9_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·the·kubelet·Certificate·File·for·the·API·Server</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cni_conf_ocil:questionnaire:1">
 89 ······<ocil:title>Verify·Group·Who·Owns·The·OpenShift·Container·Network·Interface·Files</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-api_server_kubelet_client_cert_pre_4_9_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cni_conf_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-api_server_tls_security_profile_custom_min_tls_version_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·custom·tlsSecurityProfile·configured·for·APIServer·uses·secure·TLS·version</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_vswitchd_pid_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Daemon·PID·File</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-api_server_tls_security_profile_custom_min_tls_version_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_vswitchd_pid_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-api_server_auth_mode_node_ocil:questionnaire:1">
107 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>101 ······<ocil:title>Ensure·authorization-mode·Node·is·configured</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-api_server_auth_mode_node_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-api_server_admission_control_plugin_noderestriction_ocil:questionnaire:1"> 
113 ······<ocil:title>Enable·the·NodeRestriction·Admission·Control·Plugin</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ovs_sys_id_conf_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Permissions·on·the·Open·vSwitch·Persistent·System·ID</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-api_server_admission_control_plugin_noderestriction_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ovs_sys_id_conf_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-routes_rate_limit_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·that·all·Routes·has·rate·limit·enabled</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_cipher_suites_openshiftapiserver_operator_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·that·the·OpenShift·API·Server·Operator·only·makes·use·of·Strong·Cryptographic·Ciphers</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-routes_rate_limit_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_cipher_suites_openshiftapiserver_operator_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 846858/859860 bytes (98.49%) of diff not shown.
1.82 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
1.82 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml">oval:ssg-installed_OS_is_ol10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Oracle·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 307, 25 lines modifiedOffset 307, 25 lines modified
307 ··········</cpe-lang:logical-test>307 ··········</cpe-lang:logical-test>
308 ········</cpe-lang:platform>308 ········</cpe-lang:platform>
309 ········<cpe-lang:platform·id="package_bash">309 ········<cpe-lang:platform·id="package_bash">
310 ··········<cpe-lang:logical-test·operator="AND"·negate="false">310 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
311 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>311 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
312 ··········</cpe-lang:logical-test>312 ··········</cpe-lang:logical-test>
313 ········</cpe-lang:platform>313 ········</cpe-lang:platform>
314 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
315 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
317 ··········</cpe-lang:logical-test> 
318 ········</cpe-lang:platform> 
319 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">314 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
320 ··········<cpe-lang:logical-test·operator="AND"·negate="false">315 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
321 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
322 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>317 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
323 ··········</cpe-lang:logical-test>318 ··········</cpe-lang:logical-test>
324 ········</cpe-lang:platform>319 ········</cpe-lang:platform>
 320 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 321 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 322 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 323 ··········</cpe-lang:logical-test>
 324 ········</cpe-lang:platform>
325 ········<cpe-lang:platform·id="not_s390x_arch">325 ········<cpe-lang:platform·id="not_s390x_arch">
326 ··········<cpe-lang:logical-test·operator="AND"·negate="false">326 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
328 ··········</cpe-lang:logical-test>328 ··········</cpe-lang:logical-test>
329 ········</cpe-lang:platform>329 ········</cpe-lang:platform>
330 ········<cpe-lang:platform·id="package_tmux">330 ········<cpe-lang:platform·id="package_tmux">
331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 194138, 15 lines modifiedOffset 194138, 15 lines modified
194138 ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/>194138 ··············<xccdf-1.2:check-content-ref·href="ssg-ol10-ocil.xml"·name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/>
194139 ············</xccdf-1.2:check>194139 ············</xccdf-1.2:check>
194140 ··········</xccdf-1.2:Rule>194140 ··········</xccdf-1.2:Rule>
194141 ········</xccdf-1.2:Group>194141 ········</xccdf-1.2:Group>
194142 ······</xccdf-1.2:Group>194142 ······</xccdf-1.2:Group>
194143 ····</xccdf-1.2:Benchmark>194143 ····</xccdf-1.2:Benchmark>
194144 ··</ds:component>194144 ··</ds:component>
194145 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-02-28T20:08:00">194145 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-oval.xml"·timestamp="2025-03-01T22:08:00">
194146 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">194146 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
194147 ······<oval-def:generator>194147 ······<oval-def:generator>
194148 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>194148 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
194149 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>194149 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
194150 ········<oval:schema_version>5.11</oval:schema_version>194150 ········<oval:schema_version>5.11</oval:schema_version>
194151 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>194151 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
194152 ······</oval-def:generator>194152 ······</oval-def:generator>
Offset 237580, 11997 lines modifiedOffset 237580, 12092 lines modified
237580 ············</oval-def:arithmetic>237580 ············</oval-def:arithmetic>
237581 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>237581 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
237582 ··········</oval-def:arithmetic>237582 ··········</oval-def:arithmetic>
237583 ········</oval-def:local_variable>237583 ········</oval-def:local_variable>
237584 ······</oval-def:variables>237584 ······</oval-def:variables>
237585 ····</oval-def:oval_definitions>237585 ····</oval-def:oval_definitions>
237586 ··</ds:component>237586 ··</ds:component>
237587 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-02-28T20:08:00">237587 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol10-ocil.xml"·timestamp="2025-03-01T22:08:00">
237588 ····<ocil:ocil>237588 ····<ocil:ocil>
237589 ······<ocil:generator>237589 ······<ocil:generator>
237590 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>237590 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
237591 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>237591 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
237592 ········<ocil:schema_version>2.0</ocil:schema_version>237592 ········<ocil:schema_version>2.0</ocil:schema_version>
237593 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>237593 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
237594 ······</ocil:generator>237594 ······</ocil:generator>
237595 ······<ocil:questionnaires>237595 ······<ocil:questionnaires>
237596 ········<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">237596 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postdrop_ocil:questionnaire:1">
 237597 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postdrop</ocil:title>
237597 ··········<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title> 
237598 ··········<ocil:actions> 
237599 ············<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref> 
237600 ··········</ocil:actions> 
237601 ········</ocil:questionnaire> 
237602 ········<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1"> 
237603 ··········<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title> 
237604 ··········<ocil:actions> 
237605 ············<ocil:test_action_ref>ocil:ssg-directory_access_var_log_audit_action:testaction:1</ocil:test_action_ref> 
237606 ··········</ocil:actions> 
237607 ········</ocil:questionnaire> 
237608 ········<ocil:questionnaire·id="ocil:ssg-mount_option_opt_nosuid_ocil:questionnaire:1"> 
237609 ··········<ocil:title>Add·nosuid·Option·to·/opt</ocil:title> 
237610 ··········<ocil:actions> 
237611 ············<ocil:test_action_ref>ocil:ssg-mount_option_opt_nosuid_action:testaction:1</ocil:test_action_ref> 
237612 ··········</ocil:actions> 
237613 ········</ocil:questionnaire> 
237614 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"> 
237615 ··········<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title> 
237616 ··········<ocil:actions> 
237617 ············<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref> 
237618 ··········</ocil:actions> 
237619 ········</ocil:questionnaire> 
237620 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"> 
237621 ··········<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title> 
237622 ··········<ocil:actions> 
237623 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_percentage_action:testaction:1</ocil:test_action_ref> 
237624 ··········</ocil:actions> 
237625 ········</ocil:questionnaire> 
237626 ········<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1"> 
237627 ··········<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title> 
237628 ··········<ocil:actions>237598 ··········<ocil:actions>
237629 ············<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>237599 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postdrop_action:testaction:1</ocil:test_action_ref>
237630 ··········</ocil:actions>237600 ··········</ocil:actions>
237631 ········</ocil:questionnaire>237601 ········</ocil:questionnaire>
237632 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">237602 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
237633 ··········<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>237603 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
237634 ··········<ocil:actions>237604 ··········<ocil:actions>
Max diff block lines reached; 1895449/1905165 bytes (99.49%) of diff not shown.
1.74 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
1.74 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
Ordering differences only
    
Offset 3, 15690 lines modifiedOffset 3, 15114 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postdrop_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postdrop</ocil:title>
11 ······<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Access·Events·to·Audit·Log·Directory</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-directory_access_var_log_audit_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_opt_nosuid_ocil:questionnaire:1"> 
23 ······<ocil:title>Add·nosuid·Option·to·/opt</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-mount_option_opt_nosuid_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"> 
29 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title> 
30 ······<ocil:actions> 
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref> 
32 ······</ocil:actions> 
33 ····</ocil:questionnaire> 
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·space_left·on·Low·Disk·Space</ocil:title> 
36 ······<ocil:actions> 
37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_percentage_action:testaction:1</ocil:test_action_ref> 
38 ······</ocil:actions> 
39 ····</ocil:questionnaire> 
40 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1"> 
41 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title> 
42 ······<ocil:actions>12 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postdrop_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>14 ······</ocil:actions>
45 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
 17 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·and·Unloading</ocil:title>
48 ······<ocil:actions>18 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>20 ······</ocil:actions>
51 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1"> 
53 ······<ocil:title>The·operating·system·must·restrict·privilege·elevation·to·authorized·personnel</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_dot_no_world_writable_programs_ocil:questionnaire:1">
 23 ······<ocil:title>User·Initialization·Files·Must·Not·Run·World-Writable·Programs</ocil:title>
54 ······<ocil:actions>24 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_user_dot_no_world_writable_programs_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>26 ······</ocil:actions>
57 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1">
59 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>29 ······<ocil:title>Add·noexec·Option·to·/var/tmp</ocil:title>
60 ······<ocil:actions>30 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>32 ······</ocil:actions>
63 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-service_rlogin_disabled_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>35 ······<ocil:title>Disable·rlogin·Service</ocil:title>
66 ······<ocil:actions>36 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-service_rlogin_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>38 ······</ocil:actions>
69 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>41 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>
72 ······<ocil:actions>42 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>44 ······</ocil:actions>
75 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fsetxattr_ocil:questionnaire:1"> 
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fsetxattr</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">
 47 ······<ocil:title>Install·AIDE</ocil:title>
78 ······<ocil:actions>48 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>50 ······</ocil:actions>
81 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
83 ······<ocil:title>Require·Re-Authentication·When·Using·the·sudo·Command</ocil:title>53 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>
84 ······<ocil:actions>54 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>56 ······</ocil:actions>
87 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-service_nftables_disabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-grub2_page_alloc_shuffle_argument_ocil:questionnaire:1">
89 ······<ocil:title>Verify·nftables·Service·is·Disabled</ocil:title>59 ······<ocil:title>Enable·randomization·of·the·page·allocator</ocil:title>
90 ······<ocil:actions>60 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-service_nftables_disabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-grub2_page_alloc_shuffle_argument_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>62 ······</ocil:actions>
93 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_remote_filesystems_ocil:questionnaire:1"> 
95 ······<ocil:title>Mount·Remote·Filesystems·with·noexec</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-disable_ctrlaltdel_reboot_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·Ctrl-Alt-Del·Reboot·Activation</ocil:title>
96 ······<ocil:actions>66 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-mount_option_noexec_remote_filesystems_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-disable_ctrlaltdel_reboot_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>68 ······</ocil:actions>
99 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_srv_nosuid_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
101 ······<ocil:title>Add·nosuid·Option·to·/srv</ocil:title>71 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
102 ······<ocil:actions>72 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-mount_option_srv_nosuid_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>74 ······</ocil:actions>
105 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1"> 
107 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">
 77 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>
108 ······<ocil:actions>78 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>80 ······</ocil:actions>
111 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>83 ······<ocil:title>Enable·FIPS·Mode</ocil:title>
114 ······<ocil:actions>84 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>86 ······</ocil:actions>
117 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"> 
119 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·No·Device·Files·are·Unlabeled·by·SELinux</ocil:title>
120 ······<ocil:actions>90 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>92 ······</ocil:actions>
Max diff block lines reached; 1812157/1823285 bytes (99.39%) of diff not shown.
2.28 KB
./usr/share/xml/scap/ssg/content/ssg-ol10-xccdf.xml
2.18 KB
./usr/share/xml/scap/ssg/content/ssg-ol10-xccdf.xml
Ordering differences only
    
Offset 274, 25 lines modifiedOffset 274, 25 lines modified
274 ······</cpe-lang:logical-test>274 ······</cpe-lang:logical-test>
275 ····</cpe-lang:platform>275 ····</cpe-lang:platform>
276 ····<cpe-lang:platform·id="package_bash">276 ····<cpe-lang:platform·id="package_bash">
277 ······<cpe-lang:logical-test·operator="AND"·negate="false">277 ······<cpe-lang:logical-test·operator="AND"·negate="false">
278 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>278 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
279 ······</cpe-lang:logical-test>279 ······</cpe-lang:logical-test>
280 ····</cpe-lang:platform>280 ····</cpe-lang:platform>
281 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
282 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
284 ······</cpe-lang:logical-test> 
285 ····</cpe-lang:platform> 
286 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">281 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
287 ······<cpe-lang:logical-test·operator="AND"·negate="false">282 ······<cpe-lang:logical-test·operator="AND"·negate="false">
288 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
289 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>284 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
290 ······</cpe-lang:logical-test>285 ······</cpe-lang:logical-test>
291 ····</cpe-lang:platform>286 ····</cpe-lang:platform>
 287 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 288 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 289 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 290 ······</cpe-lang:logical-test>
 291 ····</cpe-lang:platform>
292 ····<cpe-lang:platform·id="not_s390x_arch">292 ····<cpe-lang:platform·id="not_s390x_arch">
293 ······<cpe-lang:logical-test·operator="AND"·negate="false">293 ······<cpe-lang:logical-test·operator="AND"·negate="false">
294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
295 ······</cpe-lang:logical-test>295 ······</cpe-lang:logical-test>
296 ····</cpe-lang:platform>296 ····</cpe-lang:platform>
297 ····<cpe-lang:platform·id="package_tmux">297 ····<cpe-lang:platform·id="package_tmux">
298 ······<cpe-lang:logical-test·operator="AND"·negate="false">298 ······<cpe-lang:logical-test·operator="AND"·negate="false">
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol7-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol7-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol7.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol7.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:7">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·7</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml">oval:ssg-installed_OS_is_ol7:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-7"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·7</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·7.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 355, 25 lines modifiedOffset 355, 25 lines modified
355 ··········</cpe-lang:logical-test>355 ··········</cpe-lang:logical-test>
356 ········</cpe-lang:platform>356 ········</cpe-lang:platform>
357 ········<cpe-lang:platform·id="package_bash">357 ········<cpe-lang:platform·id="package_bash">
358 ··········<cpe-lang:logical-test·operator="AND"·negate="false">358 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
359 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>359 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
360 ··········</cpe-lang:logical-test>360 ··········</cpe-lang:logical-test>
361 ········</cpe-lang:platform>361 ········</cpe-lang:platform>
362 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
363 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
364 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
365 ··········</cpe-lang:logical-test> 
366 ········</cpe-lang:platform> 
367 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">362 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
368 ··········<cpe-lang:logical-test·operator="AND"·negate="false">363 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
369 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>364 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>365 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
371 ··········</cpe-lang:logical-test>366 ··········</cpe-lang:logical-test>
372 ········</cpe-lang:platform>367 ········</cpe-lang:platform>
 368 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 369 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 370 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 371 ··········</cpe-lang:logical-test>
 372 ········</cpe-lang:platform>
373 ········<cpe-lang:platform·id="not_s390x_arch">373 ········<cpe-lang:platform·id="not_s390x_arch">
374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">374 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>375 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
376 ··········</cpe-lang:logical-test>376 ··········</cpe-lang:logical-test>
377 ········</cpe-lang:platform>377 ········</cpe-lang:platform>
378 ········<cpe-lang:platform·id="package_shadow-utils">378 ········<cpe-lang:platform·id="package_shadow-utils">
379 ··········<cpe-lang:logical-test·operator="AND"·negate="false">379 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 237865, 15 lines modifiedOffset 237865, 15 lines modified
237865 ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>237865 ··············<xccdf-1.2:check-content-ref·href="ssg-ol7-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
237866 ············</xccdf-1.2:check>237866 ············</xccdf-1.2:check>
237867 ··········</xccdf-1.2:Rule>237867 ··········</xccdf-1.2:Rule>
237868 ········</xccdf-1.2:Group>237868 ········</xccdf-1.2:Group>
237869 ······</xccdf-1.2:Group>237869 ······</xccdf-1.2:Group>
237870 ····</xccdf-1.2:Benchmark>237870 ····</xccdf-1.2:Benchmark>
237871 ··</ds:component>237871 ··</ds:component>
237872 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-02-28T20:08:00">237872 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-oval.xml"·timestamp="2025-03-01T22:08:00">
237873 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">237873 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
237874 ······<oval-def:generator>237874 ······<oval-def:generator>
237875 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>237875 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
237876 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>237876 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
237877 ········<oval:schema_version>5.11</oval:schema_version>237877 ········<oval:schema_version>5.11</oval:schema_version>
237878 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>237878 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
237879 ······</oval-def:generator>237879 ······</oval-def:generator>
Offset 286201, 9359 lines modifiedOffset 286201, 9359 lines modified
286201 ············</oval-def:arithmetic>286201 ············</oval-def:arithmetic>
286202 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>286202 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
286203 ··········</oval-def:arithmetic>286203 ··········</oval-def:arithmetic>
286204 ········</oval-def:local_variable>286204 ········</oval-def:local_variable>
286205 ······</oval-def:variables>286205 ······</oval-def:variables>
286206 ····</oval-def:oval_definitions>286206 ····</oval-def:oval_definitions>
286207 ··</ds:component>286207 ··</ds:component>
286208 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-02-28T20:08:00">286208 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol7-ocil.xml"·timestamp="2025-03-01T22:08:00">
286209 ····<ocil:ocil>286209 ····<ocil:ocil>
286210 ······<ocil:generator>286210 ······<ocil:generator>
286211 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>286211 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
286212 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>286212 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
286213 ········<ocil:schema_version>2.0</ocil:schema_version>286213 ········<ocil:schema_version>2.0</ocil:schema_version>
286214 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>286214 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
286215 ······</ocil:generator>286215 ······</ocil:generator>
286216 ······<ocil:questionnaires>286216 ······<ocil:questionnaires>
286217 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">286217 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfiles_ocil:questionnaire:1">
 286218 ··········<ocil:title>Record·Any·Attempts·to·Run·setfiles</ocil:title>
286218 ··········<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title> 
286219 ··········<ocil:actions> 
286220 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref> 
286221 ··········</ocil:actions> 
286222 ········</ocil:questionnaire> 
286223 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1"> 
286224 ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title> 
286225 ··········<ocil:actions>286219 ··········<ocil:actions>
286226 ············<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>286220 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfiles_action:testaction:1</ocil:test_action_ref>
286227 ··········</ocil:actions>286221 ··········</ocil:actions>
286228 ········</ocil:questionnaire>286222 ········</ocil:questionnaire>
286229 ········<ocil:questionnaire·id="ocil:ssg-sssd_memcache_timeout_ocil:questionnaire:1">286223 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
286230 ··········<ocil:title>Configure·SSSD's·Memory·Cache·to·Expire</ocil:title>286224 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
286231 ··········<ocil:actions>286225 ··········<ocil:actions>
286232 ············<ocil:test_action_ref>ocil:ssg-sssd_memcache_timeout_action:testaction:1</ocil:test_action_ref>286226 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
286233 ··········</ocil:actions>286227 ··········</ocil:actions>
286234 ········</ocil:questionnaire>286228 ········</ocil:questionnaire>
286235 ········<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> 
286236 ··········<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>286229 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1">
 286230 ··········<ocil:title>Disallow·kernel·profiling·by·unprivileged·users</ocil:title>
286237 ··········<ocil:actions>286231 ··········<ocil:actions>
286238 ············<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>286232 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_paranoid_action:testaction:1</ocil:test_action_ref>
286239 ··········</ocil:actions>286233 ··········</ocil:actions>
286240 ········</ocil:questionnaire>286234 ········</ocil:questionnaire>
286241 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgidmap_ocil:questionnaire:1"> 
286242 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newgidmap</ocil:title>286235 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_nodev_ocil:questionnaire:1">
 286236 ··········<ocil:title>Add·nodev·Option·to·/var</ocil:title>
286243 ··········<ocil:actions>286237 ··········<ocil:actions>
286244 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgidmap_action:testaction:1</ocil:test_action_ref>286238 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_nodev_action:testaction:1</ocil:test_action_ref>
286245 ··········</ocil:actions>286239 ··········</ocil:actions>
286246 ········</ocil:questionnaire>286240 ········</ocil:questionnaire>
286247 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1">286241 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1">
286248 ··········<ocil:title>Disable·DCCP·Support</ocil:title>286242 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·crontab</ocil:title>
286249 ··········<ocil:actions>286243 ··········<ocil:actions>
286250 ············<ocil:test_action_ref>ocil:ssg-kernel_module_dccp_disabled_action:testaction:1</ocil:test_action_ref>286244 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1</ocil:test_action_ref>
286251 ··········</ocil:actions>286245 ··········</ocil:actions>
286252 ········</ocil:questionnaire>286246 ········</ocil:questionnaire>
286253 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">286247 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">
Max diff block lines reached; 2286282/2296995 bytes (99.53%) of diff not shown.
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
Ordering differences only
    
Offset 3, 9350 lines modifiedOffset 3, 9350 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfiles_ocil:questionnaire:1">
 11 ······<ocil:title>Record·Any·Attempts·to·Run·setfiles</ocil:title>
11 ······<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfiles_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sssd_memcache_timeout_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
23 ······<ocil:title>Configure·SSSD's·Memory·Cache·to·Expire</ocil:title>17 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sssd_memcache_timeout_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> 
29 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1">
 23 ······<ocil:title>Disallow·kernel·profiling·by·unprivileged·users</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_paranoid_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgidmap_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newgidmap</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_nodev_ocil:questionnaire:1">
 29 ······<ocil:title>Add·nodev·Option·to·/var</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgidmap_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_nodev_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1">
41 ······<ocil:title>Disable·DCCP·Support</ocil:title>35 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·crontab</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_module_dccp_disabled_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">
47 ······<ocil:title>Set·SSH·Client·Alive·Interval</ocil:title>41 ······<ocil:title>Randomize·the·address·of·the·kernel·image·(KASLR)</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_base_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
53 ······<ocil:title>Set·type·of·computer·node·name·logging·in·audit·logs</ocil:title>47 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1"> 
59 ······<ocil:title>Disable·xinetd·Service</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·auditd·Unauthorized·Access·Attempts·To·open_by_handle_at·Are·Ordered·Correctly</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">
65 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>59 ······<ocil:title>Uninstall·bind·Package</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1">
71 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title>65 ······<ocil:title>Install·scap-security-guide·Package</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_system_commands_dirs_ocil:questionnaire:1">
77 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>71 ······<ocil:title>Verify·that·system·commands·files·are·group·owned·by·root·or·a·system·account</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_system_commands_dirs_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_lastlog_ocil:questionnaire:1">
83 ······<ocil:title>Install·AIDE</ocil:title>77 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·lastlog</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_lastlog_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_mode_blank_ocil:questionnaire:1"> 
89 ······<ocil:title>Implement·Blank·Screensaver</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-sebool_guest_exec_content_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·the·guest_exec_content·SELinux·Boolean</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_mode_blank_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sebool_guest_exec_content_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·su</ocil:title>89 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_user_list_ocil:questionnaire:1"> 
101 ······<ocil:title>Disable·the·GNOME3·Login·User·List</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_user_list_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudoers_default_includedir_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·sudo·only·includes·the·default·configuration·directory</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudoers_default_includedir_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_crypttab_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·All·User·Initialization·Files·Have·Mode·0740·Or·Less·Permissive</ocil:title>107 ······<ocil:title>Verify·Permissions·On·/etc/crypttab·File</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_crypttab_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1">
119 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>113 ······<ocil:title>Verify·Group·Who·Owns·/etc/selinux·Directory</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_selinux_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
Max diff block lines reached; 2185048/2197289 bytes (99.44%) of diff not shown.
2.28 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
2.18 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
Ordering differences only
    
Offset 320, 25 lines modifiedOffset 320, 25 lines modified
320 ······</cpe-lang:logical-test>320 ······</cpe-lang:logical-test>
321 ····</cpe-lang:platform>321 ····</cpe-lang:platform>
322 ····<cpe-lang:platform·id="package_bash">322 ····<cpe-lang:platform·id="package_bash">
323 ······<cpe-lang:logical-test·operator="AND"·negate="false">323 ······<cpe-lang:logical-test·operator="AND"·negate="false">
324 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>324 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
325 ······</cpe-lang:logical-test>325 ······</cpe-lang:logical-test>
326 ····</cpe-lang:platform>326 ····</cpe-lang:platform>
327 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
328 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
329 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
330 ······</cpe-lang:logical-test> 
331 ····</cpe-lang:platform> 
332 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">327 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
333 ······<cpe-lang:logical-test·operator="AND"·negate="false">328 ······<cpe-lang:logical-test·operator="AND"·negate="false">
334 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>329 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
335 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>330 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
336 ······</cpe-lang:logical-test>331 ······</cpe-lang:logical-test>
337 ····</cpe-lang:platform>332 ····</cpe-lang:platform>
 333 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 334 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 335 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 336 ······</cpe-lang:logical-test>
 337 ····</cpe-lang:platform>
338 ····<cpe-lang:platform·id="not_s390x_arch">338 ····<cpe-lang:platform·id="not_s390x_arch">
339 ······<cpe-lang:logical-test·operator="AND"·negate="false">339 ······<cpe-lang:logical-test·operator="AND"·negate="false">
340 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>340 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
341 ······</cpe-lang:logical-test>341 ······</cpe-lang:logical-test>
342 ····</cpe-lang:platform>342 ····</cpe-lang:platform>
343 ····<cpe-lang:platform·id="package_shadow-utils">343 ····<cpe-lang:platform·id="package_shadow-utils">
344 ······<cpe-lang:logical-test·operator="AND"·negate="false">344 ······<cpe-lang:logical-test·operator="AND"·negate="false">
2.59 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
2.59 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol8-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol8.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol8.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:8">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·8</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml">oval:ssg-installed_OS_is_ol8:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·8</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·8.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 264643, 15 lines modifiedOffset 264643, 15 lines modified
264643 ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>264643 ··············<xccdf-1.2:check-content-ref·href="ssg-ol8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
264644 ············</xccdf-1.2:check>264644 ············</xccdf-1.2:check>
264645 ··········</xccdf-1.2:Rule>264645 ··········</xccdf-1.2:Rule>
264646 ········</xccdf-1.2:Group>264646 ········</xccdf-1.2:Group>
264647 ······</xccdf-1.2:Group>264647 ······</xccdf-1.2:Group>
264648 ····</xccdf-1.2:Benchmark>264648 ····</xccdf-1.2:Benchmark>
264649 ··</ds:component>264649 ··</ds:component>
264650 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-02-28T20:08:00">264650 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-oval.xml"·timestamp="2025-03-01T22:08:00">
264651 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">264651 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
264652 ······<oval-def:generator>264652 ······<oval-def:generator>
264653 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>264653 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
264654 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>264654 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
264655 ········<oval:schema_version>5.11</oval:schema_version>264655 ········<oval:schema_version>5.11</oval:schema_version>
264656 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>264656 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
264657 ······</oval-def:generator>264657 ······</oval-def:generator>
Offset 321125, 9185 lines modifiedOffset 321125, 9185 lines modified
321125 ············</oval-def:arithmetic>321125 ············</oval-def:arithmetic>
321126 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>321126 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
321127 ··········</oval-def:arithmetic>321127 ··········</oval-def:arithmetic>
321128 ········</oval-def:local_variable>321128 ········</oval-def:local_variable>
321129 ······</oval-def:variables>321129 ······</oval-def:variables>
321130 ····</oval-def:oval_definitions>321130 ····</oval-def:oval_definitions>
321131 ··</ds:component>321131 ··</ds:component>
321132 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-02-28T20:08:00">321132 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol8-ocil.xml"·timestamp="2025-03-01T22:08:00">
321133 ····<ocil:ocil>321133 ····<ocil:ocil>
321134 ······<ocil:generator>321134 ······<ocil:generator>
321135 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>321135 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
321136 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>321136 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
321137 ········<ocil:schema_version>2.0</ocil:schema_version>321137 ········<ocil:schema_version>2.0</ocil:schema_version>
321138 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>321138 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
321139 ······</ocil:generator>321139 ······</ocil:generator>
321140 ······<ocil:questionnaires>321140 ······<ocil:questionnaires>
 321141 ········<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_sudoersd_ocil:questionnaire:1">
 321142 ··········<ocil:title>Verify·User·Who·Owns·/etc/sudoers.d·Directory</ocil:title>
 321143 ··········<ocil:actions>
 321144 ············<ocil:test_action_ref>ocil:ssg-directory_owner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>
 321145 ··········</ocil:actions>
 321146 ········</ocil:questionnaire>
321141 ········<ocil:questionnaire·id="ocil:ssg-sebool_gpg_web_anon_write_ocil:questionnaire:1">321147 ········<ocil:questionnaire·id="ocil:ssg-sebool_gpg_web_anon_write_ocil:questionnaire:1">
321142 ··········<ocil:title>Disable·the·gpg_web_anon_write·SELinux·Boolean</ocil:title>321148 ··········<ocil:title>Disable·the·gpg_web_anon_write·SELinux·Boolean</ocil:title>
321143 ··········<ocil:actions>321149 ··········<ocil:actions>
321144 ············<ocil:test_action_ref>ocil:ssg-sebool_gpg_web_anon_write_action:testaction:1</ocil:test_action_ref>321150 ············<ocil:test_action_ref>ocil:ssg-sebool_gpg_web_anon_write_action:testaction:1</ocil:test_action_ref>
321145 ··········</ocil:actions>321151 ··········</ocil:actions>
321146 ········</ocil:questionnaire>321152 ········</ocil:questionnaire>
321147 ········<ocil:questionnaire·id="ocil:ssg-package_dnf-automatic_installed_ocil:questionnaire:1"> 
321148 ··········<ocil:title>Install·dnf-automatic·Package</ocil:title>321153 ········<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">
 321154 ··········<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>
321149 ··········<ocil:actions>321155 ··········<ocil:actions>
321150 ············<ocil:test_action_ref>ocil:ssg-package_dnf-automatic_installed_action:testaction:1</ocil:test_action_ref>321156 ············<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
321151 ··········</ocil:actions>321157 ··········</ocil:actions>
321152 ········</ocil:questionnaire>321158 ········</ocil:questionnaire>
321153 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">321159 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
321154 ··········<ocil:title>Verify·permissions·on·Message·of·the·Day·Banner</ocil:title>321160 ··········<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
321155 ··········<ocil:actions>321161 ··········<ocil:actions>
321156 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>321162 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
321157 ··········</ocil:actions>321163 ··········</ocil:actions>
321158 ········</ocil:questionnaire>321164 ········</ocil:questionnaire>
321159 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_configure_remote_server_ocil:questionnaire:1"> 
321160 ··········<ocil:title>Configure·audispd·Plugin·To·Send·Logs·To·Remote·Server</ocil:title>321165 ········<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1">
 321166 ··········<ocil:title>Set·PAM''s·Password·Hashing·Algorithm·-·password-auth</ocil:title>
321161 ··········<ocil:actions>321167 ··········<ocil:actions>
321162 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_configure_remote_server_action:testaction:1</ocil:test_action_ref>321168 ············<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_passwordauth_action:testaction:1</ocil:test_action_ref>
321163 ··········</ocil:actions>321169 ··········</ocil:actions>
321164 ········</ocil:questionnaire>321170 ········</ocil:questionnaire>
321165 ········<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_ocil:questionnaire:1">321171 ········<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">
321166 ··········<ocil:title>Disable·the·selinuxuser_postgresql_connect_enabled·SELinux·Boolean</ocil:title>321172 ··········<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>
321167 ··········<ocil:actions>321173 ··········<ocil:actions>
321168 ············<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_action:testaction:1</ocil:test_action_ref>321174 ············<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>
321169 ··········</ocil:actions>321175 ··········</ocil:actions>
321170 ········</ocil:questionnaire>321176 ········</ocil:questionnaire>
321171 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1">321177 ········<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
321172 ··········<ocil:title>Set·GNOME3·Screensaver·Inactivity·Timeout</ocil:title>321178 ··········<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>
321173 ··········<ocil:actions>321179 ··········<ocil:actions>
321174 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1</ocil:test_action_ref>321180 ············<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>
321175 ··········</ocil:actions>321181 ··········</ocil:actions>
321176 ········</ocil:questionnaire>321182 ········</ocil:questionnaire>
321177 ········<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1"> 
321178 ··········<ocil:title>Disable·snmpd·Service</ocil:title>321183 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_ocil:questionnaire:1">
 321184 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·pam_timestamp_check</ocil:title>
321179 ··········<ocil:actions>321185 ··········<ocil:actions>
321180 ············<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>321186 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_action:testaction:1</ocil:test_action_ref>
321181 ··········</ocil:actions>321187 ··········</ocil:actions>
321182 ········</ocil:questionnaire>321188 ········</ocil:questionnaire>
321183 ········<ocil:questionnaire·id="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1">321189 ········<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">
321184 ··········<ocil:title>System·Audit·Logs·Must·Be·Group·Owned·By·Root</ocil:title>321190 ··········<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>
321185 ··········<ocil:actions>321191 ··········<ocil:actions>
321186 ············<ocil:test_action_ref>ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>321192 ············<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>
321187 ··········</ocil:actions>321193 ··········</ocil:actions>
321188 ········</ocil:questionnaire>321194 ········</ocil:questionnaire>
321189 ········<ocil:questionnaire·id="ocil:ssg-enable_dconf_user_profile_ocil:questionnaire:1">321195 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
321190 ··········<ocil:title>Configure·GNOME3·DConf·User·Profile</ocil:title>321196 ··········<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
321191 ··········<ocil:actions>321197 ··········<ocil:actions>
321192 ············<ocil:test_action_ref>ocil:ssg-enable_dconf_user_profile_action:testaction:1</ocil:test_action_ref>321198 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
321193 ··········</ocil:actions>321199 ··········</ocil:actions>
321194 ········</ocil:questionnaire>321200 ········</ocil:questionnaire>
321195 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1"> 
321196 ··········<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>321201 ········<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1">
 321202 ··········<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title>
321197 ··········<ocil:actions>321203 ··········<ocil:actions>
321198 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>321204 ············<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref>
321199 ··········</ocil:actions>321205 ··········</ocil:actions>
321200 ········</ocil:questionnaire>321206 ········</ocil:questionnaire>
321201 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">321207 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nosuid_ocil:questionnaire:1">
Max diff block lines reached; 2700308/2711930 bytes (99.57%) of diff not shown.
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
2.48 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
Ordering differences only
    
Offset 3, 9176 lines modifiedOffset 3, 9176 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_sudoersd_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·User·Who·Owns·/etc/sudoers.d·Directory</ocil:title>
 12 ······<ocil:actions>
 13 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>
 14 ······</ocil:actions>
 15 ····</ocil:questionnaire>
10 ····<ocil:questionnaire·id="ocil:ssg-sebool_gpg_web_anon_write_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sebool_gpg_web_anon_write_ocil:questionnaire:1">
11 ······<ocil:title>Disable·the·gpg_web_anon_write·SELinux·Boolean</ocil:title>17 ······<ocil:title>Disable·the·gpg_web_anon_write·SELinux·Boolean</ocil:title>
12 ······<ocil:actions>18 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sebool_gpg_web_anon_write_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sebool_gpg_web_anon_write_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>20 ······</ocil:actions>
15 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-package_dnf-automatic_installed_ocil:questionnaire:1"> 
17 ······<ocil:title>Install·dnf-automatic·Package</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">
 23 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>
18 ······<ocil:actions>24 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_dnf-automatic_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>26 ······</ocil:actions>
21 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
23 ······<ocil:title>Verify·permissions·on·Message·of·the·Day·Banner</ocil:title>29 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
24 ······<ocil:actions>30 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>32 ······</ocil:actions>
27 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_configure_remote_server_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·audispd·Plugin·To·Send·Logs·To·Remote·Server</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1">
 35 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm·-·password-auth</ocil:title>
30 ······<ocil:actions>36 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_configure_remote_server_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_passwordauth_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>38 ······</ocil:actions>
33 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">
35 ······<ocil:title>Disable·the·selinuxuser_postgresql_connect_enabled·SELinux·Boolean</ocil:title>41 ······<ocil:title>Verify·Owner·on·SSH·Server·config·file</ocil:title>
36 ······<ocil:actions>42 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>44 ······</ocil:actions>
39 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
41 ······<ocil:title>Set·GNOME3·Screensaver·Inactivity·Timeout</ocil:title>47 ······<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>
42 ······<ocil:actions>48 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>50 ······</ocil:actions>
45 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1"> 
47 ······<ocil:title>Disable·snmpd·Service</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·pam_timestamp_check</ocil:title>
48 ······<ocil:actions>54 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>56 ······</ocil:actions>
51 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">
53 ······<ocil:title>System·Audit·Logs·Must·Be·Group·Owned·By·Root</ocil:title>59 ······<ocil:title>Add·nosuid·Option·to·/var/log/audit</ocil:title>
54 ······<ocil:actions>60 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>62 ······</ocil:actions>
57 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-enable_dconf_user_profile_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
59 ······<ocil:title>Configure·GNOME3·DConf·User·Profile</ocil:title>65 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>
60 ······<ocil:actions>66 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-enable_dconf_user_profile_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>68 ······</ocil:actions>
63 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1"> 
65 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title>
66 ······<ocil:actions>72 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>74 ······</ocil:actions>
69 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_nosuid_ocil:questionnaire:1">
71 ······<ocil:title>Avoid·speculative·indirect·branches·in·kernel</ocil:title>77 ······<ocil:title>Add·nosuid·Option·to·/boot</ocil:title>
72 ······<ocil:actions>78 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_retpoline_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_nosuid_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>80 ······</ocil:actions>
75 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> 
77 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_kmod_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·kmod</ocil:title>
78 ······<ocil:actions>84 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_kmod_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>86 ······</ocil:actions>
81 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-install_antivirus_ocil:questionnaire:1">
83 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls</ocil:title>89 ······<ocil:title>Install·Virus·Scanning·Software</ocil:title>
84 ······<ocil:actions>90 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-install_antivirus_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>92 ······</ocil:actions>
87 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1">
89 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>95 ······<ocil:title>Verify·Who·Owns·/etc/shells·File</ocil:title>
90 ······<ocil:actions>96 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shells_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>98 ······</ocil:actions>
93 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_rear_installed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">
95 ······<ocil:title>Install·rear·Package</ocil:title>101 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Authentication·Retry·Prompts·Permitted·Per-Session</ocil:title>
96 ······<ocil:actions>102 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_rear_installed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>104 ······</ocil:actions>
99 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_dir_ocil:questionnaire:1"> 
101 ······<ocil:title>Lock·Accounts·Must·Persist</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_execstack_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·the·selinuxuser_execstack·SELinux·Boolean</ocil:title>
102 ······<ocil:actions>108 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execstack_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>110 ······</ocil:actions>
105 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_group_open_ocil:questionnaire:1">
107 ······<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title>113 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open·syscall·-·/etc/group</ocil:title>
108 ······<ocil:actions>114 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>116 ······</ocil:actions>
111 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1"> 
113 ······<ocil:title>Limit·Password·Reuse</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
 119 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
114 ······<ocil:actions>120 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 2587774/2599882 bytes (99.53%) of diff not shown.
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
    
Offset 21, 23 lines modifiedOffset 21, 23 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ol9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ol9-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_security-oval-com.oracle.elsa-ol9.xml.bz2"·xlink:href="https://linux.oracle.com/security/oval/com.oracle.elsa-ol9.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">30 ······<cpe-dict:cpe-item·name="cpe:/o:oracle:linux:9">
31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">Oracle·Linux·9</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml">oval:ssg-installed_OS_is_ol9:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ····</cpe-dict:cpe-list>34 ····</cpe-dict:cpe-list>
35 ··</ds:component>35 ··</ds:component>
36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-02-28T20:08:00">36 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">37 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>38 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>39 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Oracle·Linux·9</xccdf-1.2:title>
40 ······<xccdf-1.2:description>40 ······<xccdf-1.2:description>
41 ········This·guide·presents·a·catalog·of·security-relevant41 ········This·guide·presents·a·catalog·of·security-relevant
42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of42 configuration·settings·for·Oracle·Linux·9.·It·is·a·rendering·of
43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)43 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 370, 25 lines modifiedOffset 370, 25 lines modified
370 ··········</cpe-lang:logical-test>370 ··········</cpe-lang:logical-test>
371 ········</cpe-lang:platform>371 ········</cpe-lang:platform>
372 ········<cpe-lang:platform·id="package_bash">372 ········<cpe-lang:platform·id="package_bash">
373 ··········<cpe-lang:logical-test·operator="AND"·negate="false">373 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
374 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>374 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
375 ··········</cpe-lang:logical-test>375 ··········</cpe-lang:logical-test>
376 ········</cpe-lang:platform>376 ········</cpe-lang:platform>
377 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
378 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
379 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
380 ··········</cpe-lang:logical-test> 
381 ········</cpe-lang:platform> 
382 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">377 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
383 ··········<cpe-lang:logical-test·operator="AND"·negate="false">378 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
384 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>379 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
385 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>380 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
386 ··········</cpe-lang:logical-test>381 ··········</cpe-lang:logical-test>
387 ········</cpe-lang:platform>382 ········</cpe-lang:platform>
 383 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 384 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 385 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 386 ··········</cpe-lang:logical-test>
 387 ········</cpe-lang:platform>
388 ········<cpe-lang:platform·id="not_s390x_arch">388 ········<cpe-lang:platform·id="not_s390x_arch">
389 ··········<cpe-lang:logical-test·operator="AND"·negate="false">389 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
390 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>390 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
391 ··········</cpe-lang:logical-test>391 ··········</cpe-lang:logical-test>
392 ········</cpe-lang:platform>392 ········</cpe-lang:platform>
393 ········<cpe-lang:platform·id="package_tmux">393 ········<cpe-lang:platform·id="package_tmux">
394 ··········<cpe-lang:logical-test·operator="AND"·negate="false">394 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 204458, 15 lines modifiedOffset 204458, 15 lines modified
204458 ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/>204458 ··············<xccdf-1.2:check-content-ref·href="ssg-ol9-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/>
204459 ············</xccdf-1.2:check>204459 ············</xccdf-1.2:check>
204460 ··········</xccdf-1.2:Rule>204460 ··········</xccdf-1.2:Rule>
204461 ········</xccdf-1.2:Group>204461 ········</xccdf-1.2:Group>
204462 ······</xccdf-1.2:Group>204462 ······</xccdf-1.2:Group>
204463 ····</xccdf-1.2:Benchmark>204463 ····</xccdf-1.2:Benchmark>
204464 ··</ds:component>204464 ··</ds:component>
204465 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-02-28T20:08:00">204465 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-oval.xml"·timestamp="2025-03-01T22:08:00">
204466 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">204466 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
204467 ······<oval-def:generator>204467 ······<oval-def:generator>
204468 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>204468 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
204469 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>204469 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
204470 ········<oval:schema_version>5.11</oval:schema_version>204470 ········<oval:schema_version>5.11</oval:schema_version>
204471 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>204471 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
204472 ······</oval-def:generator>204472 ······</oval-def:generator>
Offset 250354, 10053 lines modifiedOffset 250354, 10053 lines modified
250354 ············</oval-def:arithmetic>250354 ············</oval-def:arithmetic>
250355 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>250355 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
250356 ··········</oval-def:arithmetic>250356 ··········</oval-def:arithmetic>
250357 ········</oval-def:local_variable>250357 ········</oval-def:local_variable>
250358 ······</oval-def:variables>250358 ······</oval-def:variables>
250359 ····</oval-def:oval_definitions>250359 ····</oval-def:oval_definitions>
250360 ··</ds:component>250360 ··</ds:component>
250361 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-02-28T20:08:00">250361 ··<ds:component·id="scap_org.open-scap_comp_ssg-ol9-ocil.xml"·timestamp="2025-03-01T22:08:00">
250362 ····<ocil:ocil>250362 ····<ocil:ocil>
250363 ······<ocil:generator>250363 ······<ocil:generator>
250364 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>250364 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
250365 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>250365 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
250366 ········<ocil:schema_version>2.0</ocil:schema_version>250366 ········<ocil:schema_version>2.0</ocil:schema_version>
250367 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>250367 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
250368 ······</ocil:generator>250368 ······</ocil:generator>
250369 ······<ocil:questionnaires>250369 ······<ocil:questionnaires>
250370 ········<ocil:questionnaire·id="ocil:ssg-package_iprutils_removed_ocil:questionnaire:1">250370 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_vsyscall_emulate_ocil:questionnaire:1">
250371 ··········<ocil:title>Uninstall·iprutils·Package</ocil:title>250371 ··········<ocil:title>Disable·vsyscall·emulation</ocil:title>
250372 ··········<ocil:actions>250372 ··········<ocil:actions>
250373 ············<ocil:test_action_ref>ocil:ssg-package_iprutils_removed_action:testaction:1</ocil:test_action_ref>250373 ············<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_vsyscall_emulate_action:testaction:1</ocil:test_action_ref>
250374 ··········</ocil:actions>250374 ··········</ocil:actions>
250375 ········</ocil:questionnaire>250375 ········</ocil:questionnaire>
250376 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_remote_access_encryption_ocil:questionnaire:1">250376 ········<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">
250377 ··········<ocil:title>Require·Encryption·for·Remote·Access·in·GNOME3</ocil:title>250377 ··········<ocil:title>Uninstall·tftp-server·Package</ocil:title>
250378 ··········<ocil:actions>250378 ··········<ocil:actions>
250379 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_remote_access_encryption_action:testaction:1</ocil:test_action_ref>250379 ············<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>
250380 ··········</ocil:actions>250380 ··········</ocil:actions>
250381 ········</ocil:questionnaire>250381 ········</ocil:questionnaire>
250382 ········<ocil:questionnaire·id="ocil:ssg-fapolicy_default_deny_ocil:questionnaire:1">250382 ········<ocil:questionnaire·id="ocil:ssg-configure_usbguard_auditbackend_ocil:questionnaire:1">
250383 ··········<ocil:title>Configure·Fapolicy·Module·to·Employ·a·Deny-all,·Permit-by-exception·Policy·to·Allow·the·Execution·of·Authorized·Software·Programs.</ocil:title>250383 ··········<ocil:title>Log·USBGuard·daemon·audit·events·using·Linux·Audit</ocil:title>
250384 ··········<ocil:actions>250384 ··········<ocil:actions>
250385 ············<ocil:test_action_ref>ocil:ssg-fapolicy_default_deny_action:testaction:1</ocil:test_action_ref>250385 ············<ocil:test_action_ref>ocil:ssg-configure_usbguard_auditbackend_action:testaction:1</ocil:test_action_ref>
250386 ··········</ocil:actions>250386 ··········</ocil:actions>
250387 ········</ocil:questionnaire>250387 ········</ocil:questionnaire>
250388 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1">250388 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
250389 ··········<ocil:title>Disable·the·uvcvideo·module</ocil:title>250389 ··········<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
250390 ··········<ocil:actions>250390 ··········<ocil:actions>
250391 ············<ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>250391 ············<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
250392 ··········</ocil:actions>250392 ··········</ocil:actions>
250393 ········</ocil:questionnaire>250393 ········</ocil:questionnaire>
250394 ········<ocil:questionnaire·id="ocil:ssg-firewalld-backend_ocil:questionnaire:1">250394 ········<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">
250395 ··········<ocil:title>Configure·Firewalld·to·Use·the·Nftables·Backend</ocil:title>250395 ··········<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>
250396 ··········<ocil:actions>250396 ··········<ocil:actions>
250397 ············<ocil:test_action_ref>ocil:ssg-firewalld-backend_action:testaction:1</ocil:test_action_ref>250397 ············<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>
250398 ··········</ocil:actions>250398 ··········</ocil:actions>
250399 ········</ocil:questionnaire>250399 ········</ocil:questionnaire>
250400 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">250400 ········<ocil:questionnaire·id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">
250401 ··········<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>250401 ··········<ocil:title>Use·Centralized·and·Automated·Authentication</ocil:title>
250402 ··········<ocil:actions>250402 ··········<ocil:actions>
250403 ············<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>250403 ············<ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>
250404 ··········</ocil:actions>250404 ··········</ocil:actions>
250405 ········</ocil:questionnaire>250405 ········</ocil:questionnaire>
250406 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1"> 
250407 ··········<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>250406 ········<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1">
 250407 ··········<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
250408 ··········<ocil:actions>250408 ··········<ocil:actions>
Max diff block lines reached; 2144731/2156037 bytes (99.48%) of diff not shown.
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
Ordering differences only
    
Offset 3, 10044 lines modifiedOffset 3, 10044 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_iprutils_removed_ocil:questionnaire:1"> 
11 ······<ocil:title>Uninstall·iprutils·Package</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_vsyscall_emulate_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·vsyscall·emulation</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-package_iprutils_removed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_vsyscall_emulate_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_remote_access_encryption_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">
17 ······<ocil:title>Require·Encryption·for·Remote·Access·in·GNOME3</ocil:title>17 ······<ocil:title>Uninstall·tftp-server·Package</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_remote_access_encryption_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-fapolicy_default_deny_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-configure_usbguard_auditbackend_ocil:questionnaire:1">
23 ······<ocil:title>Configure·Fapolicy·Module·to·Employ·a·Deny-all,·Permit-by-exception·Policy·to·Allow·the·Execution·of·Authorized·Software·Programs.</ocil:title>23 ······<ocil:title>Log·USBGuard·daemon·audit·events·using·Linux·Audit</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-fapolicy_default_deny_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-configure_usbguard_auditbackend_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
29 ······<ocil:title>Disable·the·uvcvideo·module</ocil:title>29 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-firewalld-backend_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">
35 ······<ocil:title>Configure·Firewalld·to·Use·the·Nftables·Backend</ocil:title>35 ······<ocil:title>Add·nosuid·Option·to·/boot/efi</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-firewalld-backend_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>41 ······<ocil:title>Use·Centralized·and·Automated·Authentication</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1">
 47 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
53 ······<ocil:title>Configure·Accepting·Default·Router·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>53 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-dir_group_ownership_library_dirs_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">
59 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Group·Ownership</ocil:title>59 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-dir_group_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1">
65 ······<ocil:title>Restrict·unprivileged·access·to·the·kernel·syslog</ocil:title>65 ······<ocil:title>Configure·the·confidence·in·TPM·for·entropy</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-service_oddjobd_disabled_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Odd·Job·Daemon·(oddjobd)</ocil:title>71 ······<ocil:title>Install·firewalld·Package</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-service_oddjobd_disabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_efi_user_cfg_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Graphical·Environment·Startup·By·Setting·Default·Target</ocil:title>77 ······<ocil:title>Verify·/boot/grub2/user.cfg·User·Ownership</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_owner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_tmux_installed_ocil:questionnaire:1"> 
83 ······<ocil:title>Install·the·tmux·Package</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_system_commands_dirs_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·that·system·commands·files·are·group·owned·by·root·or·a·system·account</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_tmux_installed_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_system_commands_dirs_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1"> 
89 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_accept_default_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·Access·to·Network·bpf()·Syscall·From·Unprivileged·Processes</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_accept_default_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·User</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_binary_dirs_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
107 ······<ocil:title>Verify·that·System·Executables·Have·Restrictive·Permissions</ocil:title>107 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1"> 
113 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
 113 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_perm_change_failed_ocil:questionnaire:1">
119 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>119 ······<ocil:title>Configure·auditing·of·unsuccessful·permission·changes</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-audit_perm_change_failed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 2050313/2063049 bytes (99.38%) of diff not shown.
2.27 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
2.17 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
Ordering differences only
    
Offset 335, 25 lines modifiedOffset 335, 25 lines modified
335 ······</cpe-lang:logical-test>335 ······</cpe-lang:logical-test>
336 ····</cpe-lang:platform>336 ····</cpe-lang:platform>
337 ····<cpe-lang:platform·id="package_bash">337 ····<cpe-lang:platform·id="package_bash">
338 ······<cpe-lang:logical-test·operator="AND"·negate="false">338 ······<cpe-lang:logical-test·operator="AND"·negate="false">
339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
340 ······</cpe-lang:logical-test>340 ······</cpe-lang:logical-test>
341 ····</cpe-lang:platform>341 ····</cpe-lang:platform>
342 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
343 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
345 ······</cpe-lang:logical-test> 
346 ····</cpe-lang:platform> 
347 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">342 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
348 ······<cpe-lang:logical-test·operator="AND"·negate="false">343 ······<cpe-lang:logical-test·operator="AND"·negate="false">
349 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>345 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
351 ······</cpe-lang:logical-test>346 ······</cpe-lang:logical-test>
352 ····</cpe-lang:platform>347 ····</cpe-lang:platform>
 348 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 349 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 351 ······</cpe-lang:logical-test>
 352 ····</cpe-lang:platform>
353 ····<cpe-lang:platform·id="not_s390x_arch">353 ····<cpe-lang:platform·id="not_s390x_arch">
354 ······<cpe-lang:logical-test·operator="AND"·negate="false">354 ······<cpe-lang:logical-test·operator="AND"·negate="false">
355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
356 ······</cpe-lang:logical-test>356 ······</cpe-lang:logical-test>
357 ····</cpe-lang:platform>357 ····</cpe-lang:platform>
358 ····<cpe-lang:platform·id="package_tmux">358 ····<cpe-lang:platform·id="package_tmux">
359 ······<cpe-lang:logical-test·operator="AND"·negate="false">359 ······<cpe-lang:logical-test·operator="AND"·negate="false">
941 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
941 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">
29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">
33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">
41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 59078, 15 lines modifiedOffset 59078, 15 lines modified
59078 ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>59078 ··············<xccdf-1.2:check-content-ref·href="ssg-openembedded-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
59079 ············</xccdf-1.2:check>59079 ············</xccdf-1.2:check>
59080 ··········</xccdf-1.2:Rule>59080 ··········</xccdf-1.2:Rule>
59081 ········</xccdf-1.2:Group>59081 ········</xccdf-1.2:Group>
59082 ······</xccdf-1.2:Group>59082 ······</xccdf-1.2:Group>
59083 ····</xccdf-1.2:Benchmark>59083 ····</xccdf-1.2:Benchmark>
59084 ··</ds:component>59084 ··</ds:component>
59085 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-02-28T20:08:00">59085 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-oval.xml"·timestamp="2025-03-01T22:08:00">
59086 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">59086 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
59087 ······<oval-def:generator>59087 ······<oval-def:generator>
59088 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>59088 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
59089 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>59089 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
59090 ········<oval:schema_version>5.11</oval:schema_version>59090 ········<oval:schema_version>5.11</oval:schema_version>
59091 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>59091 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
59092 ······</oval-def:generator>59092 ······</oval-def:generator>
Offset 81150, 3530 lines modifiedOffset 81150, 3530 lines modified
81150 ············</oval-def:arithmetic>81150 ············</oval-def:arithmetic>
81151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>81151 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
81152 ··········</oval-def:arithmetic>81152 ··········</oval-def:arithmetic>
81153 ········</oval-def:local_variable>81153 ········</oval-def:local_variable>
81154 ······</oval-def:variables>81154 ······</oval-def:variables>
81155 ····</oval-def:oval_definitions>81155 ····</oval-def:oval_definitions>
81156 ··</ds:component>81156 ··</ds:component>
81157 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-02-28T20:08:00">81157 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-ocil.xml"·timestamp="2025-03-01T22:08:00">
81158 ····<ocil:ocil>81158 ····<ocil:ocil>
81159 ······<ocil:generator>81159 ······<ocil:generator>
81160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>81160 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
81161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>81161 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
81162 ········<ocil:schema_version>2.0</ocil:schema_version>81162 ········<ocil:schema_version>2.0</ocil:schema_version>
81163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>81163 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
81164 ······</ocil:generator>81164 ······</ocil:generator>
81165 ······<ocil:questionnaires>81165 ······<ocil:questionnaires>
81166 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">81166 ········<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">
81167 ··········<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>81167 ··········<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>
81168 ··········<ocil:actions>81168 ··········<ocil:actions>
81169 ············<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>81169 ············<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>
81170 ··········</ocil:actions>81170 ··········</ocil:actions>
81171 ········</ocil:questionnaire>81171 ········</ocil:questionnaire>
81172 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1"> 
81173 ··········<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>81172 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 81173 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
81174 ··········<ocil:actions>81174 ··········<ocil:actions>
81175 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>81175 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
81176 ··········</ocil:actions>81176 ··········</ocil:actions>
81177 ········</ocil:questionnaire>81177 ········</ocil:questionnaire>
81178 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">81178 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
81179 ··········<ocil:title>Specify·module·signing·key·to·use</ocil:title>81179 ··········<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
81180 ··········<ocil:actions>81180 ··········<ocil:actions>
81181 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>81181 ············<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
81182 ··········</ocil:actions>81182 ··········</ocil:actions>
81183 ········</ocil:questionnaire>81183 ········</ocil:questionnaire>
81184 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> 
81185 ··········<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>81184 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
 81185 ··········<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
81186 ··········<ocil:actions>81186 ··········<ocil:actions>
81187 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>81187 ············<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
81188 ··········</ocil:actions>81188 ··········</ocil:actions>
81189 ········</ocil:questionnaire>81189 ········</ocil:questionnaire>
81190 ········<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">81190 ········<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
81191 ··········<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>81191 ··········<ocil:title>Limit·Users'·SSH·Access</ocil:title>
81192 ··········<ocil:actions>81192 ··········<ocil:actions>
81193 ············<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>81193 ············<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
81194 ··········</ocil:actions>81194 ··········</ocil:actions>
81195 ········</ocil:questionnaire>81195 ········</ocil:questionnaire>
81196 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">81196 ········<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
81197 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>81197 ··········<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
81198 ··········<ocil:actions>81198 ··········<ocil:actions>
81199 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>81199 ············<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
81200 ··········</ocil:actions>81200 ··········</ocil:actions>
81201 ········</ocil:questionnaire>81201 ········</ocil:questionnaire>
81202 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">81202 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">
81203 ··········<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>81203 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>
81204 ··········<ocil:actions>81204 ··········<ocil:actions>
81205 ············<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>81205 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
81206 ··········</ocil:actions>81206 ··········</ocil:actions>
81207 ········</ocil:questionnaire>81207 ········</ocil:questionnaire>
81208 ········<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">81208 ········<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">
81209 ··········<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>81209 ··········<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>
81210 ··········<ocil:actions>81210 ··········<ocil:actions>
81211 ············<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>81211 ············<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>
81212 ··········</ocil:actions>81212 ··········</ocil:actions>
81213 ········</ocil:questionnaire>81213 ········</ocil:questionnaire>
81214 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">81214 ········<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
81215 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>81215 ··········<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
81216 ··········<ocil:actions>81216 ··········<ocil:actions>
81217 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>81217 ············<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
81218 ··········</ocil:actions>81218 ··········</ocil:actions>
81219 ········</ocil:questionnaire>81219 ········</ocil:questionnaire>
81220 ········<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">81220 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
81221 ··········<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>81221 ··········<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
81222 ··········<ocil:actions>81222 ··········<ocil:actions>
81223 ············<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>81223 ············<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
81224 ··········</ocil:actions>81224 ··········</ocil:actions>
81225 ········</ocil:questionnaire>81225 ········</ocil:questionnaire>
81226 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">81226 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
Max diff block lines reached; 951472/963556 bytes (98.75%) of diff not shown.
897 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
897 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
Ordering differences only
    
Offset 3, 3521 lines modifiedOffset 3, 3521 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·renameat</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">
 11 ······<ocil:title>Enforce·Spectre·v2·mitigation</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
23 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>23 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Root·Ownership</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"> 
29 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
 29 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
35 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>35 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>41 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">
47 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>53 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
59 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>59 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
65 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>65 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlinkat</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
 71 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>77 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_allow_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Who·Owns·/etc/cron.allow·file</ocil:title>83 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_allow_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">
89 ······<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>89 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·the·confidence·in·TPM·for·entropy</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> 
101 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
 101 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">
 107 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">
113 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>113 ······<ocil:title>Disable·IA32·emulation</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1"> 
119 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
 119 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 905871/918266 bytes (98.65%) of diff not shown.
554 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
554 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 39461, 15 lines modifiedOffset 39461, 15 lines modified
39461 ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/>39461 ··············<xccdf-1.2:check-content-ref·href="ssg-openeuler2203-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/>
39462 ············</xccdf-1.2:check>39462 ············</xccdf-1.2:check>
39463 ··········</xccdf-1.2:Rule>39463 ··········</xccdf-1.2:Rule>
39464 ········</xccdf-1.2:Group>39464 ········</xccdf-1.2:Group>
39465 ······</xccdf-1.2:Group>39465 ······</xccdf-1.2:Group>
39466 ····</xccdf-1.2:Benchmark>39466 ····</xccdf-1.2:Benchmark>
39467 ··</ds:component>39467 ··</ds:component>
39468 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-02-28T20:08:00">39468 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"·timestamp="2025-03-01T22:08:00">
39469 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">39469 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
39470 ······<oval-def:generator>39470 ······<oval-def:generator>
39471 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>39471 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
39472 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>39472 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
39473 ········<oval:schema_version>5.11</oval:schema_version>39473 ········<oval:schema_version>5.11</oval:schema_version>
39474 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>39474 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
39475 ······</oval-def:generator>39475 ······</oval-def:generator>
Offset 52232, 3310 lines modifiedOffset 52232, 3310 lines modified
52232 ············</oval-def:arithmetic>52232 ············</oval-def:arithmetic>
52233 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>52233 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
52234 ··········</oval-def:arithmetic>52234 ··········</oval-def:arithmetic>
52235 ········</oval-def:local_variable>52235 ········</oval-def:local_variable>
52236 ······</oval-def:variables>52236 ······</oval-def:variables>
52237 ····</oval-def:oval_definitions>52237 ····</oval-def:oval_definitions>
52238 ··</ds:component>52238 ··</ds:component>
52239 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-02-28T20:08:00">52239 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"·timestamp="2025-03-01T22:08:00">
52240 ····<ocil:ocil>52240 ····<ocil:ocil>
52241 ······<ocil:generator>52241 ······<ocil:generator>
52242 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>52242 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
52243 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>52243 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
52244 ········<ocil:schema_version>2.0</ocil:schema_version>52244 ········<ocil:schema_version>2.0</ocil:schema_version>
52245 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>52245 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
52246 ······</ocil:generator>52246 ······</ocil:generator>
52247 ······<ocil:questionnaires>52247 ······<ocil:questionnaires>
52248 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> 
52249 ··········<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title> 
52250 ··········<ocil:actions> 
52251 ············<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref> 
52252 ··········</ocil:actions> 
52253 ········</ocil:questionnaire> 
52254 ········<ocil:questionnaire·id="ocil:ssg-package_ypserv_removed_ocil:questionnaire:1">52248 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
52255 ··········<ocil:title>Uninstall·ypserv·Package</ocil:title>52249 ··········<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
52256 ··········<ocil:actions>52250 ··········<ocil:actions>
52257 ············<ocil:test_action_ref>ocil:ssg-package_ypserv_removed_action:testaction:1</ocil:test_action_ref>52251 ············<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
52258 ··········</ocil:actions>52252 ··········</ocil:actions>
52259 ········</ocil:questionnaire>52253 ········</ocil:questionnaire>
52260 ········<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1">52254 ········<ocil:questionnaire·id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">
52261 ··········<ocil:title>Ensure·remote·access·methods·are·monitored·in·Rsyslog</ocil:title>52255 ··········<ocil:title>Disable·graphical·user·interface</ocil:title>
52262 ··········<ocil:actions>52256 ··········<ocil:actions>
52263 ············<ocil:test_action_ref>ocil:ssg-rsyslog_remote_access_monitoring_action:testaction:1</ocil:test_action_ref>52257 ············<ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>
52264 ··········</ocil:actions>52258 ··········</ocil:actions>
52265 ········</ocil:questionnaire>52259 ········</ocil:questionnaire>
52266 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_disk_full_action_ocil:questionnaire:1">52260 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">
52267 ··········<ocil:title>Configure·audispd's·Plugin·disk_full_action·When·Disk·Is·Full</ocil:title>52261 ··········<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>
52268 ··········<ocil:actions>52262 ··········<ocil:actions>
52269 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_disk_full_action_action:testaction:1</ocil:test_action_ref>52263 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>
52270 ··········</ocil:actions>52264 ··········</ocil:actions>
52271 ········</ocil:questionnaire>52265 ········</ocil:questionnaire>
52272 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">52266 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
52273 ··········<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>52267 ··········<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
52274 ··········<ocil:actions>52268 ··········<ocil:actions>
52275 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>52269 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
52276 ··········</ocil:actions>52270 ··········</ocil:actions>
52277 ········</ocil:questionnaire>52271 ········</ocil:questionnaire>
52278 ········<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1"> 
52279 ··········<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>52272 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1">
 52273 ··········<ocil:title>Verify·Permissions·on·cron.daily</ocil:title>
52280 ··········<ocil:actions>52274 ··········<ocil:actions>
52281 ············<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>52275 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref>
52282 ··········</ocil:actions>52276 ··········</ocil:actions>
52283 ········</ocil:questionnaire>52277 ········</ocil:questionnaire>
52284 ········<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">52278 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
52285 ··········<ocil:title>The·Chronyd·service·is·enabled</ocil:title>52279 ··········<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
52286 ··········<ocil:actions>52280 ··········<ocil:actions>
52287 ············<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>52281 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
52288 ··········</ocil:actions>52282 ··········</ocil:actions>
52289 ········</ocil:questionnaire>52283 ········</ocil:questionnaire>
52290 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1"> 
52291 ··········<ocil:title>Record·Successful·Permission·Changes·to·Files·-·lsetxattr</ocil:title>52284 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
 52285 ··········<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
52292 ··········<ocil:actions>52286 ··········<ocil:actions>
52293 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>52287 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
52294 ··········</ocil:actions>52288 ··········</ocil:actions>
52295 ········</ocil:questionnaire>52289 ········</ocil:questionnaire>
52296 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">52290 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_kex_ocil:questionnaire:1">
52297 ··········<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>52291 ··········<ocil:title>Use·Only·Strong·Key·Exchange·algorithms</ocil:title>
52298 ··········<ocil:actions>52292 ··········<ocil:actions>
52299 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>52293 ············<ocil:test_action_ref>ocil:ssg-sshd_use_strong_kex_action:testaction:1</ocil:test_action_ref>
52300 ··········</ocil:actions>52294 ··········</ocil:actions>
52301 ········</ocil:questionnaire>52295 ········</ocil:questionnaire>
52302 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1"> 
52303 ··········<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>52296 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_percentage_ocil:questionnaire:1">
 52297 ··········<ocil:title>Configure·auditd·admin_space_left·on·Low·Disk·Space</ocil:title>
52304 ··········<ocil:actions>52298 ··········<ocil:actions>
52305 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>52299 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_percentage_action:testaction:1</ocil:test_action_ref>
52306 ··········</ocil:actions>52300 ··········</ocil:actions>
52307 ········</ocil:questionnaire>52301 ········</ocil:questionnaire>
Max diff block lines reached; 555164/567094 bytes (97.90%) of diff not shown.
525 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
525 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
Ordering differences only
    
Offset 3, 3301 lines modifiedOffset 3, 3301 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
 11 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_ypserv_removed_ocil:questionnaire:1"> 
17 ······<ocil:title>Uninstall·ypserv·Package</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-package_ypserv_removed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·remote·access·methods·are·monitored·in·Rsyslog</ocil:title>17 ······<ocil:title>Disable·graphical·user·interface</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_access_monitoring_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_disk_full_action_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·audispd's·Plugin·disk_full_action·When·Disk·Is·Full</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_disk_full_action_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
35 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>29 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1"> 
41 ······<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Permissions·on·cron.daily</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
47 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>41 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1"> 
53 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·lsetxattr</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_kex_ocil:questionnaire:1">
59 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>53 ······<ocil:title>Use·Only·Strong·Key·Exchange·algorithms</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_kex_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_percentage_ocil:questionnaire:1">
 59 ······<ocil:title>Configure·auditd·admin_space_left·on·Low·Disk·Space</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_percentage_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·All·SUID·Executables·Are·Authorized</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1"> 
77 ······<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-service_ntpd_enabled_ocil:questionnaire:1">
 71 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_ntpd_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_cups_removed_ocil:questionnaire:1">
83 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>77 ······<ocil:title>Uninstall·CUPS·Package</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_cups_removed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_loopback_traffic_ocil:questionnaire:1">
89 ······<ocil:title>Enable·rsyslog·Service</ocil:title>83 ······<ocil:title>Set·nftables·Configuration·for·Loopback·Traffic</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-set_nftables_loopback_traffic_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Network·File·System·(nfs)</ocil:title>89 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> 
101 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·gpgcheck·Enabled·for·All·dnf·Package·Repositories</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
107 ······<ocil:title>Verify·ownership·of·System·Login·Banner</ocil:title>101 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·auditd·Collects·Unauthorized·Access·Attempts·to·Files·(unsuccessful)</ocil:title>107 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls·in·usr/share</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1"> 
119 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
 113 ······<ocil:title>Enable·Kernel·Paremeter·to·Log·Martian·Packets·on·all·IPv4·Interfaces·by·Default</ocil:title>
Max diff block lines reached; 525838/537810 bytes (97.77%) of diff not shown.
679 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
679 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">
29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">
33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">
41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-02-28T20:08:00">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2025-03-01T22:08:00">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·openSUSE.·It·is·a·rendering·of52 configuration·settings·for·openSUSE.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 41119, 15 lines modifiedOffset 41119, 15 lines modified
41119 ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>41119 ··············<xccdf-1.2:check-content-ref·href="ssg-opensuse-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
41120 ············</xccdf-1.2:check>41120 ············</xccdf-1.2:check>
41121 ··········</xccdf-1.2:Rule>41121 ··········</xccdf-1.2:Rule>
41122 ········</xccdf-1.2:Group>41122 ········</xccdf-1.2:Group>
41123 ······</xccdf-1.2:Group>41123 ······</xccdf-1.2:Group>
41124 ····</xccdf-1.2:Benchmark>41124 ····</xccdf-1.2:Benchmark>
41125 ··</ds:component>41125 ··</ds:component>
41126 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-02-28T20:08:00">41126 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-oval.xml"·timestamp="2025-03-01T22:08:00">
41127 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">41127 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
41128 ······<oval-def:generator>41128 ······<oval-def:generator>
41129 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>41129 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
41130 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>41130 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
41131 ········<oval:schema_version>5.11</oval:schema_version>41131 ········<oval:schema_version>5.11</oval:schema_version>
41132 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>41132 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
41133 ······</oval-def:generator>41133 ······</oval-def:generator>
Offset 56631, 7066 lines modifiedOffset 56631, 7066 lines modified
56631 ············</oval-def:arithmetic>56631 ············</oval-def:arithmetic>
56632 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>56632 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
56633 ··········</oval-def:arithmetic>56633 ··········</oval-def:arithmetic>
56634 ········</oval-def:local_variable>56634 ········</oval-def:local_variable>
56635 ······</oval-def:variables>56635 ······</oval-def:variables>
56636 ····</oval-def:oval_definitions>56636 ····</oval-def:oval_definitions>
56637 ··</ds:component>56637 ··</ds:component>
56638 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-02-28T20:08:00">56638 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-ocil.xml"·timestamp="2025-03-01T22:08:00">
56639 ····<ocil:ocil>56639 ····<ocil:ocil>
56640 ······<ocil:generator>56640 ······<ocil:generator>
56641 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>56641 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
56642 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>56642 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
56643 ········<ocil:schema_version>2.0</ocil:schema_version>56643 ········<ocil:schema_version>2.0</ocil:schema_version>
56644 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>56644 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
56645 ······</ocil:generator>56645 ······</ocil:generator>
56646 ······<ocil:questionnaires>56646 ······<ocil:questionnaires>
56647 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">56647 ········<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
56648 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>56648 ··········<ocil:title>IOMMU·configuration·directive</ocil:title>
56649 ··········<ocil:actions>56649 ··········<ocil:actions>
56650 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>56650 ············<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
56651 ··········</ocil:actions>56651 ··········</ocil:actions>
56652 ········</ocil:questionnaire>56652 ········</ocil:questionnaire>
56653 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
56654 ··········<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>56653 ········<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
 56654 ··········<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>
56655 ··········<ocil:actions>56655 ··········<ocil:actions>
56656 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>56656 ············<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
56657 ··········</ocil:actions>56657 ··········</ocil:actions>
56658 ········</ocil:questionnaire>56658 ········</ocil:questionnaire>
56659 ········<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">56659 ········<ocil:questionnaire·id="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1">
56660 ··········<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>56660 ··········<ocil:title>Verify·that·System·Executables·Have·Root·Ownership</ocil:title>
56661 ··········<ocil:actions>56661 ··········<ocil:actions>
56662 ············<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>56662 ············<ocil:test_action_ref>ocil:ssg-file_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
56663 ··········</ocil:actions>56663 ··········</ocil:actions>
56664 ········</ocil:questionnaire>56664 ········</ocil:questionnaire>
56665 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">56665 ········<ocil:questionnaire·id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1">
56666 ··········<ocil:title>Verify·Permissions·on·group·File</ocil:title>56666 ··········<ocil:title>Disable·the·uvcvideo·module</ocil:title>
56667 ··········<ocil:actions>56667 ··········<ocil:actions>
56668 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>56668 ············<ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>
56669 ··········</ocil:actions>56669 ··········</ocil:actions>
56670 ········</ocil:questionnaire>56670 ········</ocil:questionnaire>
56671 ········<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">56671 ········<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
56672 ··········<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>56672 ··········<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
56673 ··········<ocil:actions>56673 ··········<ocil:actions>
56674 ············<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>56674 ············<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
56675 ··········</ocil:actions>56675 ··········</ocil:actions>
56676 ········</ocil:questionnaire>56676 ········</ocil:questionnaire>
56677 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">56677 ········<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
56678 ··········<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>56678 ··········<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>
56679 ··········<ocil:actions>56679 ··········<ocil:actions>
56680 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>56680 ············<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
56681 ··········</ocil:actions>56681 ··········</ocil:actions>
56682 ········</ocil:questionnaire>56682 ········</ocil:questionnaire>
56683 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
56684 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>56683 ········<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
 56684 ··········<ocil:title>Enable·systemd-journald·Service</ocil:title>
56685 ··········<ocil:actions>56685 ··········<ocil:actions>
56686 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>56686 ············<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
56687 ··········</ocil:actions>56687 ··········</ocil:actions>
56688 ········</ocil:questionnaire>56688 ········</ocil:questionnaire>
56689 ········<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">56689 ········<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
56690 ··········<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>56690 ··········<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
56691 ··········<ocil:actions>56691 ··········<ocil:actions>
56692 ············<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>56692 ············<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
56693 ··········</ocil:actions>56693 ··········</ocil:actions>
56694 ········</ocil:questionnaire>56694 ········</ocil:questionnaire>
56695 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">56695 ········<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">
56696 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>56696 ··········<ocil:title>Enable·rsyslog·Service</ocil:title>
56697 ··········<ocil:actions>56697 ··········<ocil:actions>
56698 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>56698 ············<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>
56699 ··········</ocil:actions>56699 ··········</ocil:actions>
56700 ········</ocil:questionnaire>56700 ········</ocil:questionnaire>
56701 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">56701 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
56702 ··········<ocil:title>Enable·SSH·Warning·Banner</ocil:title>56702 ··········<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
56703 ··········<ocil:actions>56703 ··········<ocil:actions>
56704 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>56704 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
56705 ··········</ocil:actions>56705 ··········</ocil:actions>
56706 ········</ocil:questionnaire>56706 ········</ocil:questionnaire>
56707 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">56707 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
Max diff block lines reached; 682943/694806 bytes (98.29%) of diff not shown.
645 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
645 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
Ordering differences only
    
Offset 3, 7048 lines modifiedOffset 3, 7048 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
11 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>11 ······<ocil:title>IOMMU·configuration·directive</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
 17 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>23 ······<ocil:title>Verify·that·System·Executables·Have·Root·Ownership</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>29 ······<ocil:title>Disable·the·uvcvideo·module</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
35 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>35 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
41 ······<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>41 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
 47 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·Chrony·is·only·configured·with·the·server·directive</ocil:title>53 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>59 ······<ocil:title>Enable·rsyslog·Service</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
65 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>65 ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
71 ······<ocil:title>Enable·checks·on·credential·management</ocil:title>71 ······<ocil:title>Enable·Yama·support</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
77 ······<ocil:title>Disable·kernel·debugfs</ocil:title>77 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
83 ······<ocil:title>Verify·iptables·Enabled</ocil:title>83 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>89 ······<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">
95 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>95 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>101 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
107 ······<ocil:title>Enable·Yama·support</ocil:title>107 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
113 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>113 ······<ocil:title>Kernel·panic·oops</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
119 ······<ocil:title>Disable·SSH·Server·If·Possible</ocil:title>119 ······<ocil:title>Enable·module·signature·verification</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-service_sshd_disabled_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1"> 
125 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>124 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">
 125 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>
126 ······<ocil:actions>126 ······<ocil:actions>
Max diff block lines reached; 647348/660127 bytes (98.06%) of diff not shown.
1.62 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
1.62 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 321, 25 lines modifiedOffset 321, 25 lines modified
321 ··········</cpe-lang:logical-test>321 ··········</cpe-lang:logical-test>
322 ········</cpe-lang:platform>322 ········</cpe-lang:platform>
323 ········<cpe-lang:platform·id="package_bash">323 ········<cpe-lang:platform·id="package_bash">
324 ··········<cpe-lang:logical-test·operator="AND"·negate="false">324 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
325 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>325 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
326 ··········</cpe-lang:logical-test>326 ··········</cpe-lang:logical-test>
327 ········</cpe-lang:platform>327 ········</cpe-lang:platform>
328 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
329 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
330 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
331 ··········</cpe-lang:logical-test> 
332 ········</cpe-lang:platform> 
333 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">328 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
334 ··········<cpe-lang:logical-test·operator="AND"·negate="false">329 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
335 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>330 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
336 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>331 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
337 ··········</cpe-lang:logical-test>332 ··········</cpe-lang:logical-test>
338 ········</cpe-lang:platform>333 ········</cpe-lang:platform>
 334 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 335 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 336 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 337 ··········</cpe-lang:logical-test>
 338 ········</cpe-lang:platform>
339 ········<cpe-lang:platform·id="package_tmux">339 ········<cpe-lang:platform·id="package_tmux">
340 ··········<cpe-lang:logical-test·operator="AND"·negate="false">340 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
341 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>341 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>
342 ··········</cpe-lang:logical-test>342 ··········</cpe-lang:logical-test>
343 ········</cpe-lang:platform>343 ········</cpe-lang:platform>
344 ········<cpe-lang:platform·id="package_shadow-utils">344 ········<cpe-lang:platform·id="package_shadow-utils">
345 ··········<cpe-lang:logical-test·operator="AND"·negate="false">345 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 66389, 15 lines modifiedOffset 66389, 15 lines modified
66389 ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>66389 ··············<xccdf-1.2:check-content-ref·href="ssg-rhcos4-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
66390 ············</xccdf-1.2:check>66390 ············</xccdf-1.2:check>
66391 ··········</xccdf-1.2:Rule>66391 ··········</xccdf-1.2:Rule>
66392 ········</xccdf-1.2:Group>66392 ········</xccdf-1.2:Group>
66393 ······</xccdf-1.2:Group>66393 ······</xccdf-1.2:Group>
66394 ····</xccdf-1.2:Benchmark>66394 ····</xccdf-1.2:Benchmark>
66395 ··</ds:component>66395 ··</ds:component>
66396 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-02-28T20:08:00">66396 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-oval.xml"·timestamp="2025-03-01T22:08:00">
66397 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">66397 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
66398 ······<oval-def:generator>66398 ······<oval-def:generator>
66399 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>66399 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
66400 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>66400 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
66401 ········<oval:schema_version>5.11</oval:schema_version>66401 ········<oval:schema_version>5.11</oval:schema_version>
66402 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>66402 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
66403 ······</oval-def:generator>66403 ······</oval-def:generator>
Offset 104700, 8848 lines modifiedOffset 104700, 8848 lines modified
104700 ············</oval-def:arithmetic>104700 ············</oval-def:arithmetic>
104701 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>104701 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
104702 ··········</oval-def:arithmetic>104702 ··········</oval-def:arithmetic>
104703 ········</oval-def:local_variable>104703 ········</oval-def:local_variable>
104704 ······</oval-def:variables>104704 ······</oval-def:variables>
104705 ····</oval-def:oval_definitions>104705 ····</oval-def:oval_definitions>
104706 ··</ds:component>104706 ··</ds:component>
104707 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-02-28T20:08:00">104707 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"·timestamp="2025-03-01T22:08:00">
104708 ····<ocil:ocil>104708 ····<ocil:ocil>
104709 ······<ocil:generator>104709 ······<ocil:generator>
104710 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>104710 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
104711 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>104711 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
104712 ········<ocil:schema_version>2.0</ocil:schema_version>104712 ········<ocil:schema_version>2.0</ocil:schema_version>
104713 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>104713 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
104714 ······</ocil:generator>104714 ······</ocil:generator>
104715 ······<ocil:questionnaires>104715 ······<ocil:questionnaires>
104716 ········<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> 
104717 ··········<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title>104716 ········<ocil:questionnaire·id="ocil:ssg-harden_sshd_crypto_policy_ocil:questionnaire:1">
 104717 ··········<ocil:title>Harden·SSHD·Crypto·Policy</ocil:title>
104718 ··········<ocil:actions>104718 ··········<ocil:actions>
104719 ············<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>104719 ············<ocil:test_action_ref>ocil:ssg-harden_sshd_crypto_policy_action:testaction:1</ocil:test_action_ref>
104720 ··········</ocil:actions>104720 ··········</ocil:actions>
104721 ········</ocil:questionnaire>104721 ········</ocil:questionnaire>
104722 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">104722 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
104723 ··········<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>104723 ··········<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
104724 ··········<ocil:actions>104724 ··········<ocil:actions>
104725 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>104725 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
104726 ··········</ocil:actions>104726 ··········</ocil:actions>
104727 ········</ocil:questionnaire>104727 ········</ocil:questionnaire>
104728 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">104728 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_core_uses_pid_ocil:questionnaire:1">
104729 ··········<ocil:title>Add·nosuid·Option·to·/home</ocil:title>104729 ··········<ocil:title>Configure·file·name·of·core·dumps</ocil:title>
104730 ··········<ocil:actions>104730 ··········<ocil:actions>
104731 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>104731 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_core_uses_pid_action:testaction:1</ocil:test_action_ref>
104732 ··········</ocil:actions>104732 ··········</ocil:actions>
104733 ········</ocil:questionnaire>104733 ········</ocil:questionnaire>
104734 ········<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1">104734 ········<ocil:questionnaire·id="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1">
104735 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·init</ocil:title>104735 ··········<ocil:title>Install·libreswan·Package</ocil:title>
104736 ··········<ocil:actions>104736 ··········<ocil:actions>
104737 ············<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_init_action:testaction:1</ocil:test_action_ref>104737 ············<ocil:test_action_ref>ocil:ssg-package_libreswan_installed_action:testaction:1</ocil:test_action_ref>
104738 ··········</ocil:actions>104738 ··········</ocil:actions>
104739 ········</ocil:questionnaire>104739 ········</ocil:questionnaire>
104740 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1"> 
104741 ··········<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>104740 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_ocil:questionnaire:1">
 104741 ··········<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>
104742 ··········<ocil:actions>104742 ··········<ocil:actions>
104743 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>104743 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>
104744 ··········</ocil:actions>104744 ··········</ocil:actions>
104745 ········</ocil:questionnaire>104745 ········</ocil:questionnaire>
104746 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">104746 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
104747 ··········<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>104747 ··········<ocil:title>Enable·support·for·BUG()</ocil:title>
104748 ··········<ocil:actions>104748 ··········<ocil:actions>
104749 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>104749 ············<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
104750 ··········</ocil:actions>104750 ··········</ocil:actions>
104751 ········</ocil:questionnaire>104751 ········</ocil:questionnaire>
104752 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">104752 ········<ocil:questionnaire·id="ocil:ssg-disable_ctrlaltdel_reboot_ocil:questionnaire:1">
104753 ··········<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>104753 ··········<ocil:title>Disable·Ctrl-Alt-Del·Reboot·Activation</ocil:title>
Max diff block lines reached; 1688968/1699977 bytes (99.35%) of diff not shown.
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
Ordering differences only
    
Offset 3, 8839 lines modifiedOffset 3, 8839 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"> 
11 ······<ocil:title>Configure·audispd's·Plugin·network_failure_action·On·Network·Failure</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-harden_sshd_crypto_policy_ocil:questionnaire:1">
 11 ······<ocil:title>Harden·SSHD·Crypto·Policy</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-harden_sshd_crypto_policy_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Group·Who·Owns·Backup·gshadow·File</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_core_uses_pid_ocil:questionnaire:1">
23 ······<ocil:title>Add·nosuid·Option·to·/home</ocil:title>23 ······<ocil:title>Configure·file·name·of·core·dumps</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_core_uses_pid_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·init</ocil:title>29 ······<ocil:title>Install·libreswan·Package</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_init_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-package_libreswan_installed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_ocil:questionnaire:1">
 35 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·fsetxattr</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
41 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>41 ······<ocil:title>Enable·support·for·BUG()</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-disable_ctrlaltdel_reboot_ocil:questionnaire:1">
47 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>47 ······<ocil:title>Disable·Ctrl-Alt-Del·Reboot·Activation</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-disable_ctrlaltdel_reboot_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_sudoersd_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·User·Who·Owns·/etc/sudoers.d·Directory</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
 53 ······<ocil:title>Restrict·Exposed·Kernel·Pointer·Addresses·Access</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_nodev_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_sysctld_ocil:questionnaire:1">
59 ······<ocil:title>Add·nodev·Option·to·/var</ocil:title>59 ······<ocil:title>Verify·Group·Who·Owns·/etc/sysctl.d·Directory</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_nodev_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_sysctld_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
65 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
 65 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1"> 
71 ······<ocil:title>Add·noexec·Option·to·/var/tmp</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_fusermount3_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·fusermount3</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_fusermount3_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">
77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>77 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_ocil:questionnaire:1"> 
83 ······<ocil:title>Record·Unsuccessful·Modification·Attempts·to·Files·-·openat·O_TRUNC_WRITE</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-package_setroubleshoot-plugins_removed_ocil:questionnaire:1">
 83 ······<ocil:title>Uninstall·setroubleshoot-plugins·Package</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-package_setroubleshoot-plugins_removed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
89 ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>89 ······<ocil:title>Ensure·All·Accounts·on·the·System·Have·Unique·Names</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">
 95 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rmdir</ocil:title>101 ······<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"> 
107 ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1"> 
113 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·clock_settime</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">
 113 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">
119 ······<ocil:title>Add·nodev·Option·to·/var/tmp</ocil:title>119 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 1615052/1627726 bytes (99.22%) of diff not shown.
2.28 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
2.17 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
Ordering differences only
    
Offset 288, 25 lines modifiedOffset 288, 25 lines modified
288 ······</cpe-lang:logical-test>288 ······</cpe-lang:logical-test>
289 ····</cpe-lang:platform>289 ····</cpe-lang:platform>
290 ····<cpe-lang:platform·id="package_bash">290 ····<cpe-lang:platform·id="package_bash">
291 ······<cpe-lang:logical-test·operator="AND"·negate="false">291 ······<cpe-lang:logical-test·operator="AND"·negate="false">
292 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>292 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
293 ······</cpe-lang:logical-test>293 ······</cpe-lang:logical-test>
294 ····</cpe-lang:platform>294 ····</cpe-lang:platform>
295 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
296 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
297 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
298 ······</cpe-lang:logical-test> 
299 ····</cpe-lang:platform> 
300 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">295 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
301 ······<cpe-lang:logical-test·operator="AND"·negate="false">296 ······<cpe-lang:logical-test·operator="AND"·negate="false">
302 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>297 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
303 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>298 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
304 ······</cpe-lang:logical-test>299 ······</cpe-lang:logical-test>
305 ····</cpe-lang:platform>300 ····</cpe-lang:platform>
 301 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 302 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 303 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 304 ······</cpe-lang:logical-test>
 305 ····</cpe-lang:platform>
306 ····<cpe-lang:platform·id="package_tmux">306 ····<cpe-lang:platform·id="package_tmux">
307 ······<cpe-lang:logical-test·operator="AND"·negate="false">307 ······<cpe-lang:logical-test·operator="AND"·negate="false">
308 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>308 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>
309 ······</cpe-lang:logical-test>309 ······</cpe-lang:logical-test>
310 ····</cpe-lang:platform>310 ····</cpe-lang:platform>
311 ····<cpe-lang:platform·id="package_shadow-utils">311 ····<cpe-lang:platform·id="package_shadow-utils">
312 ······<cpe-lang:logical-test·operator="AND"·negate="false">312 ······<cpe-lang:logical-test·operator="AND"·negate="false">
2.13 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
2.13 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:10">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·10</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml">oval:ssg-installed_OS_is_rhel10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·10</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·10.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 312, 25 lines modifiedOffset 312, 25 lines modified
312 ··········</cpe-lang:logical-test>312 ··········</cpe-lang:logical-test>
313 ········</cpe-lang:platform>313 ········</cpe-lang:platform>
314 ········<cpe-lang:platform·id="package_bash">314 ········<cpe-lang:platform·id="package_bash">
315 ··········<cpe-lang:logical-test·operator="AND"·negate="false">315 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>316 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
317 ··········</cpe-lang:logical-test>317 ··········</cpe-lang:logical-test>
318 ········</cpe-lang:platform>318 ········</cpe-lang:platform>
319 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
320 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
321 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
322 ··········</cpe-lang:logical-test> 
323 ········</cpe-lang:platform> 
324 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">319 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
325 ··········<cpe-lang:logical-test·operator="AND"·negate="false">320 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
326 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>321 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>322 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
328 ··········</cpe-lang:logical-test>323 ··········</cpe-lang:logical-test>
329 ········</cpe-lang:platform>324 ········</cpe-lang:platform>
 325 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 326 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 327 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 328 ··········</cpe-lang:logical-test>
 329 ········</cpe-lang:platform>
330 ········<cpe-lang:platform·id="not_s390x_arch">330 ········<cpe-lang:platform·id="not_s390x_arch">
331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">331 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
332 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>332 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
333 ··········</cpe-lang:logical-test>333 ··········</cpe-lang:logical-test>
334 ········</cpe-lang:platform>334 ········</cpe-lang:platform>
335 ········<cpe-lang:platform·id="package_tmux">335 ········<cpe-lang:platform·id="package_tmux">
336 ··········<cpe-lang:logical-test·operator="AND"·negate="false">336 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 216676, 15 lines modifiedOffset 216676, 15 lines modified
216676 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>216676 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel10-ocil.xml"·name="ocil:ssg-audit_perm_change_success_ppc64le_ocil:questionnaire:1"/>
216677 ············</xccdf-1.2:check>216677 ············</xccdf-1.2:check>
216678 ··········</xccdf-1.2:Rule>216678 ··········</xccdf-1.2:Rule>
216679 ········</xccdf-1.2:Group>216679 ········</xccdf-1.2:Group>
216680 ······</xccdf-1.2:Group>216680 ······</xccdf-1.2:Group>
216681 ····</xccdf-1.2:Benchmark>216681 ····</xccdf-1.2:Benchmark>
216682 ··</ds:component>216682 ··</ds:component>
216683 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-02-28T20:08:00">216683 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-oval.xml"·timestamp="2025-03-01T22:08:00">
216684 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">216684 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
216685 ······<oval-def:generator>216685 ······<oval-def:generator>
216686 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>216686 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
216687 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>216687 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
216688 ········<oval:schema_version>5.11</oval:schema_version>216688 ········<oval:schema_version>5.11</oval:schema_version>
216689 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>216689 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
216690 ······</oval-def:generator>216690 ······</oval-def:generator>
Offset 266291, 6855 lines modifiedOffset 266291, 6855 lines modified
266291 ············</oval-def:arithmetic>266291 ············</oval-def:arithmetic>
266292 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>266292 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
266293 ··········</oval-def:arithmetic>266293 ··········</oval-def:arithmetic>
266294 ········</oval-def:local_variable>266294 ········</oval-def:local_variable>
266295 ······</oval-def:variables>266295 ······</oval-def:variables>
266296 ····</oval-def:oval_definitions>266296 ····</oval-def:oval_definitions>
266297 ··</ds:component>266297 ··</ds:component>
266298 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-02-28T20:08:00">266298 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel10-ocil.xml"·timestamp="2025-03-01T22:08:00">
266299 ····<ocil:ocil>266299 ····<ocil:ocil>
266300 ······<ocil:generator>266300 ······<ocil:generator>
266301 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>266301 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
266302 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>266302 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
266303 ········<ocil:schema_version>2.0</ocil:schema_version>266303 ········<ocil:schema_version>2.0</ocil:schema_version>
266304 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>266304 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
266305 ······</ocil:generator>266305 ······</ocil:generator>
266306 ······<ocil:questionnaires>266306 ······<ocil:questionnaires>
 266307 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_ocil:questionnaire:1">
 266308 ··········<ocil:title>Set·number·of·Password·Hashing·Rounds·-·system-auth</ocil:title>
266307 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1"> 
266308 ··········<ocil:title>Verify·Permissions·On·/etc/sudoers·File</ocil:title> 
266309 ··········<ocil:actions> 
266310 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_sudoers_action:testaction:1</ocil:test_action_ref> 
266311 ··········</ocil:actions> 
266312 ········</ocil:questionnaire> 
266313 ········<ocil:questionnaire·id="ocil:ssg-grub2_audit_backlog_limit_argument_ocil:questionnaire:1"> 
266314 ··········<ocil:title>Extend·Audit·Backlog·Limit·for·the·Audit·Daemon</ocil:title> 
266315 ··········<ocil:actions> 
266316 ············<ocil:test_action_ref>ocil:ssg-grub2_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref> 
266317 ··········</ocil:actions> 
266318 ········</ocil:questionnaire> 
266319 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_ocil:questionnaire:1"> 
266320 ··········<ocil:title>Set·Kernel·Parameter·to·Increase·Local·Port·Range</ocil:title> 
266321 ··········<ocil:actions> 
266322 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_local_port_range_action:testaction:1</ocil:test_action_ref> 
266323 ··········</ocil:actions> 
266324 ········</ocil:questionnaire> 
266325 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1"> 
266326 ··········<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title> 
266327 ··········<ocil:actions>266309 ··········<ocil:actions>
266328 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>266310 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_rounds_system_auth_action:testaction:1</ocil:test_action_ref>
266329 ··········</ocil:actions>266311 ··········</ocil:actions>
266330 ········</ocil:questionnaire>266312 ········</ocil:questionnaire>
266331 ········<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">266313 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
266332 ··········<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>266314 ··········<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
266333 ··········<ocil:actions>266315 ··········<ocil:actions>
266334 ············<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>266316 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
266335 ··········</ocil:actions>266317 ··········</ocil:actions>
266336 ········</ocil:questionnaire>266318 ········</ocil:questionnaire>
266337 ········<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">266319 ········<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
266338 ··········<ocil:title>Uninstall·vsftpd·Package</ocil:title>266320 ··········<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title>
266339 ··········<ocil:actions>266321 ··········<ocil:actions>
266340 ············<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>266322 ············<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
266341 ··········</ocil:actions>266323 ··········</ocil:actions>
266342 ········</ocil:questionnaire>266324 ········</ocil:questionnaire>
266343 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1">266325 ········<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">
266344 ··········<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>266326 ··········<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>
Max diff block lines reached; 2227756/2237887 bytes (99.55%) of diff not shown.
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
2.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
Ordering differences only
    
Offset 3, 6846 lines modifiedOffset 3, 6846 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·Permissions·On·/etc/sudoers·File</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_ocil:questionnaire:1">
 11 ······<ocil:title>Set·number·of·Password·Hashing·Rounds·-·system-auth</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_sudoers_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_rounds_system_auth_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-grub2_audit_backlog_limit_argument_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
17 ······<ocil:title>Extend·Audit·Backlog·Limit·for·the·Audit·Daemon</ocil:title>17 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-grub2_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_ocil:questionnaire:1"> 
23 ······<ocil:title>Set·Kernel·Parameter·to·Increase·Local·Port·Range</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
 23 ······<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_local_port_range_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>29 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-journald_storage_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-mount_option_krb_sec_remote_filesystems_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·journald·is·configured·to·write·log·files·to·persistent·disk</ocil:title>35 ······<ocil:title>Mount·Remote·Filesystems·with·Kerberos·Security</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-mount_option_krb_sec_remote_filesystems_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1"> 
41 ······<ocil:title>Uninstall·vsftpd·Package</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv4·Interfaces</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1"> 
47 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-grub2_slub_debug_argument_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">
53 ······<ocil:title>Enable·SLUB/SLAB·allocator·poisoning</ocil:title>53 ······<ocil:title>Use·Only·Strong·MACs</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-grub2_slub_debug_argument_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-network_configure_name_resolution_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_crypttab_ocil:questionnaire:1">
59 ······<ocil:title>Configure·Multiple·DNS·Servers·in·/etc/resolv.conf</ocil:title>59 ······<ocil:title>Verify·Permissions·On·/etc/crypttab·File</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-network_configure_name_resolution_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_crypttab_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·Modprobe·Loading·of·USB·Storage·Driver</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-package_audispd-plugins_installed_ocil:questionnaire:1">
71 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>71 ······<ocil:title>Install·audispd-plugins·Package</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-package_audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_can_disabled_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1">
77 ······<ocil:title>Disable·CAN·Support</ocil:title>77 ······<ocil:title>Install·policycoreutils·Package</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_module_can_disabled_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_policycoreutils_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_repo_metadata_ocil:questionnaire:1">
83 ······<ocil:title>Verify·/boot/grub2/user.cfg·Permissions</ocil:title>83 ······<ocil:title>Ensure·gpgcheck·Enabled·for·Repository·Metadata</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_repo_metadata_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_access_success_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>89 ······<ocil:title>Configure·auditing·of·successful·file·accesses</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_access_success_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-configure_kerberos_crypto_policy_ocil:questionnaire:1"> 
95 ······<ocil:title>Configure·Kerberos·to·use·System·Crypto·Policy</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-package_tmux_installed_ocil:questionnaire:1">
 95 ······<ocil:title>Install·the·tmux·Package</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-configure_kerberos_crypto_policy_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_tmux_installed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_pcsc-lite-ccid_installed_ocil:questionnaire:1"> 
101 ······<ocil:title>Install·the·pcsc-lite-ccid·package</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_iptables_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·Group·Who·Owns·/etc/iptables·Directory</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_pcsc-lite-ccid_installed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_iptables_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·TIPC·Support</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1">
 113 ······<ocil:title>Add·noexec·Option·to·/tmp</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_noexec_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_creat_ocil:questionnaire:1">
119 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>119 ······<ocil:title>Record·Unsuccessful·Creation·Attempts·to·Files·-·open·O_CREAT</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
Max diff block lines reached; 2131912/2144443 bytes (99.42%) of diff not shown.
2.3 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
2.2 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
Ordering differences only
    
Offset 279, 25 lines modifiedOffset 279, 25 lines modified
279 ······</cpe-lang:logical-test>279 ······</cpe-lang:logical-test>
280 ····</cpe-lang:platform>280 ····</cpe-lang:platform>
281 ····<cpe-lang:platform·id="package_bash">281 ····<cpe-lang:platform·id="package_bash">
282 ······<cpe-lang:logical-test·operator="AND"·negate="false">282 ······<cpe-lang:logical-test·operator="AND"·negate="false">
283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>283 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
284 ······</cpe-lang:logical-test>284 ······</cpe-lang:logical-test>
285 ····</cpe-lang:platform>285 ····</cpe-lang:platform>
286 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7"> 
287 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
288 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/> 
289 ······</cpe-lang:logical-test> 
290 ····</cpe-lang:platform> 
291 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">286 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
292 ······<cpe-lang:logical-test·operator="AND"·negate="false">287 ······<cpe-lang:logical-test·operator="AND"·negate="false">
293 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>288 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>289 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
295 ······</cpe-lang:logical-test>290 ······</cpe-lang:logical-test>
296 ····</cpe-lang:platform>291 ····</cpe-lang:platform>
 292 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
 293 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
 295 ······</cpe-lang:logical-test>
 296 ····</cpe-lang:platform>
297 ····<cpe-lang:platform·id="not_s390x_arch">297 ····<cpe-lang:platform·id="not_s390x_arch">
298 ······<cpe-lang:logical-test·operator="AND"·negate="false">298 ······<cpe-lang:logical-test·operator="AND"·negate="false">
299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
300 ······</cpe-lang:logical-test>300 ······</cpe-lang:logical-test>
301 ····</cpe-lang:platform>301 ····</cpe-lang:platform>
302 ····<cpe-lang:platform·id="package_tmux">302 ····<cpe-lang:platform·id="package_tmux">
303 ······<cpe-lang:logical-test·operator="AND"·negate="false">303 ······<cpe-lang:logical-test·operator="AND"·negate="false">
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
3.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.0">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.0</cpe-dict:title>
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ······</cpe-dict:cpe-item>71 ······</cpe-dict:cpe-item>
72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">72 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8.9">
73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>73 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·8.9</cpe-dict:title>
74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>74 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel8-cpe-oval.xml">oval:ssg-installed_OS_is_rhel8_9:def:1</cpe-dict:check>
75 ······</cpe-dict:cpe-item>75 ······</cpe-dict:cpe-item>
76 ····</cpe-dict:cpe-list>76 ····</cpe-dict:cpe-list>
77 ··</ds:component>77 ··</ds:component>
78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-02-28T20:08:00">78 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-xccdf.xml"·timestamp="2025-03-01T22:08:00">
79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">79 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>80 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>81 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
82 ······<xccdf-1.2:description>82 ······<xccdf-1.2:description>
83 ········This·guide·presents·a·catalog·of·security-relevant83 ········This·guide·presents·a·catalog·of·security-relevant
84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of84 configuration·settings·for·Red·Hat·Enterprise·Linux·8.·It·is·a·rendering·of
85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)85 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 317526, 15 lines modifiedOffset 317526, 15 lines modified
317526 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>317526 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel8-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
317527 ············</xccdf-1.2:check>317527 ············</xccdf-1.2:check>
317528 ··········</xccdf-1.2:Rule>317528 ··········</xccdf-1.2:Rule>
317529 ········</xccdf-1.2:Group>317529 ········</xccdf-1.2:Group>
317530 ······</xccdf-1.2:Group>317530 ······</xccdf-1.2:Group>
317531 ····</xccdf-1.2:Benchmark>317531 ····</xccdf-1.2:Benchmark>
317532 ··</ds:component>317532 ··</ds:component>
317533 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-02-28T20:08:00">317533 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-oval.xml"·timestamp="2025-03-01T22:08:00">
317534 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">317534 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
317535 ······<oval-def:generator>317535 ······<oval-def:generator>
317536 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>317536 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
317537 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>317537 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
317538 ········<oval:schema_version>5.11</oval:schema_version>317538 ········<oval:schema_version>5.11</oval:schema_version>
317539 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>317539 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
317540 ······</oval-def:generator>317540 ······</oval-def:generator>
Offset 385018, 11327 lines modifiedOffset 385018, 11327 lines modified
385018 ············</oval-def:arithmetic>385018 ············</oval-def:arithmetic>
385019 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>385019 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
385020 ··········</oval-def:arithmetic>385020 ··········</oval-def:arithmetic>
385021 ········</oval-def:local_variable>385021 ········</oval-def:local_variable>
385022 ······</oval-def:variables>385022 ······</oval-def:variables>
385023 ····</oval-def:oval_definitions>385023 ····</oval-def:oval_definitions>
385024 ··</ds:component>385024 ··</ds:component>
385025 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-02-28T20:08:00">385025 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel8-ocil.xml"·timestamp="2025-03-01T22:08:00">
385026 ····<ocil:ocil>385026 ····<ocil:ocil>
385027 ······<ocil:generator>385027 ······<ocil:generator>
385028 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>385028 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
385029 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>385029 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
385030 ········<ocil:schema_version>2.0</ocil:schema_version>385030 ········<ocil:schema_version>2.0</ocil:schema_version>
385031 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>385031 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
385032 ······</ocil:generator>385032 ······</ocil:generator>
385033 ······<ocil:questionnaires>385033 ······<ocil:questionnaires>
385034 ········<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1"> 
385035 ··········<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>385034 ········<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwquality_system_auth_ocil:questionnaire:1">
 385035 ··········<ocil:title>Ensure·PAM·password·complexity·module·is·enabled·in·system-auth</ocil:title>
385036 ··········<ocil:actions>385036 ··········<ocil:actions>
385037 ············<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>385037 ············<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwquality_system_auth_action:testaction:1</ocil:test_action_ref>
385038 ··········</ocil:actions>385038 ··········</ocil:actions>
385039 ········</ocil:questionnaire>385039 ········</ocil:questionnaire>
385040 ········<ocil:questionnaire·id="ocil:ssg-zipl_enable_selinux_ocil:questionnaire:1">385040 ········<ocil:questionnaire·id="ocil:ssg-httpd_antivirus_scan_uploads_ocil:questionnaire:1">
385041 ··········<ocil:title>Ensure·SELinux·Not·Disabled·in·zIPL</ocil:title>385041 ··········<ocil:title>Scan·All·Uploaded·Content·for·Malicious·Software</ocil:title>
385042 ··········<ocil:actions>385042 ··········<ocil:actions>
385043 ············<ocil:test_action_ref>ocil:ssg-zipl_enable_selinux_action:testaction:1</ocil:test_action_ref>385043 ············<ocil:test_action_ref>ocil:ssg-httpd_antivirus_scan_uploads_action:testaction:1</ocil:test_action_ref>
385044 ··········</ocil:actions>385044 ··········</ocil:actions>
385045 ········</ocil:questionnaire>385045 ········</ocil:questionnaire>
385046 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">385046 ········<ocil:questionnaire·id="ocil:ssg-sebool_deny_ptrace_ocil:questionnaire:1">
385047 ··········<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>385047 ··········<ocil:title>Disable·the·deny_ptrace·SELinux·Boolean</ocil:title>
385048 ··········<ocil:actions>385048 ··········<ocil:actions>
385049 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>385049 ············<ocil:test_action_ref>ocil:ssg-sebool_deny_ptrace_action:testaction:1</ocil:test_action_ref>
385050 ··········</ocil:actions>385050 ··········</ocil:actions>
385051 ········</ocil:questionnaire>385051 ········</ocil:questionnaire>
385052 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">385052 ········<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1">
385053 ··········<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>385053 ··········<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title>
385054 ··········<ocil:actions>385054 ··········<ocil:actions>
385055 ············<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>385055 ············<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>
385056 ··········</ocil:actions>385056 ··········</ocil:actions>
385057 ········</ocil:questionnaire>385057 ········</ocil:questionnaire>
385058 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1"> 
385059 ··········<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·open·Are·Ordered·Correctly</ocil:title>385058 ········<ocil:questionnaire·id="ocil:ssg-sebool_cups_execmem_ocil:questionnaire:1">
 385059 ··········<ocil:title>Disable·the·cups_execmem·SELinux·Boolean</ocil:title>
385060 ··········<ocil:actions>385060 ··········<ocil:actions>
385061 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_action:testaction:1</ocil:test_action_ref>385061 ············<ocil:test_action_ref>ocil:ssg-sebool_cups_execmem_action:testaction:1</ocil:test_action_ref>
385062 ··········</ocil:actions>385062 ··········</ocil:actions>
385063 ········</ocil:questionnaire>385063 ········</ocil:questionnaire>
385064 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_on_data_corruption_ocil:questionnaire:1">385064 ········<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_autorun_ocil:questionnaire:1">
385065 ··········<ocil:title>Trigger·a·kernel·BUG·when·data·corruption·is·detected</ocil:title>385065 ··········<ocil:title>Disable·GNOME3·Automount·running</ocil:title>
385066 ··········<ocil:actions>385066 ··········<ocil:actions>
385067 ············<ocil:test_action_ref>ocil:ssg-kernel_config_bug_on_data_corruption_action:testaction:1</ocil:test_action_ref>385067 ············<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_autorun_action:testaction:1</ocil:test_action_ref>
385068 ··········</ocil:actions>385068 ··········</ocil:actions>
385069 ········</ocil:questionnaire>385069 ········</ocil:questionnaire>
385070 ········<ocil:questionnaire·id="ocil:ssg-service_abrtd_disabled_ocil:questionnaire:1">385070 ········<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
385071 ··········<ocil:title>Disable·Automatic·Bug·Reporting·Tool·(abrtd)</ocil:title>385071 ··········<ocil:title>Enable·Public·Key·Authentication</ocil:title>
385072 ··········<ocil:actions>385072 ··········<ocil:actions>
385073 ············<ocil:test_action_ref>ocil:ssg-service_abrtd_disabled_action:testaction:1</ocil:test_action_ref>385073 ············<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
385074 ··········</ocil:actions>385074 ··········</ocil:actions>
385075 ········</ocil:questionnaire>385075 ········</ocil:questionnaire>
385076 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_restorecon_ocil:questionnaire:1">385076 ········<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">
385077 ··········<ocil:title>Record·Any·Attempts·to·Run·restorecon</ocil:title>385077 ··········<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>
385078 ··········<ocil:actions>385078 ··········<ocil:actions>
385079 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_restorecon_action:testaction:1</ocil:test_action_ref>385079 ············<ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>
385080 ··········</ocil:actions>385080 ··········</ocil:actions>
385081 ········</ocil:questionnaire>385081 ········</ocil:questionnaire>
385082 ········<ocil:questionnaire·id="ocil:ssg-mount_option_home_grpquota_ocil:questionnaire:1">385082 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_tmp_ocil:questionnaire:1">
385083 ··········<ocil:title>Add·grpquota·Option·to·/home</ocil:title>385083 ··········<ocil:title>Ensure·/var/tmp·Located·On·Separate·Partition</ocil:title>
385084 ··········<ocil:actions>385084 ··········<ocil:actions>
385085 ············<ocil:test_action_ref>ocil:ssg-mount_option_home_grpquota_action:testaction:1</ocil:test_action_ref>385085 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_tmp_action:testaction:1</ocil:test_action_ref>
385086 ··········</ocil:actions>385086 ··········</ocil:actions>
385087 ········</ocil:questionnaire>385087 ········</ocil:questionnaire>
385088 ········<ocil:questionnaire·id="ocil:ssg-encrypt_partitions_ocil:questionnaire:1">385088 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">
385089 ··········<ocil:title>Encrypt·Partitions</ocil:title>385089 ··········<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>
385090 ··········<ocil:actions>385090 ··········<ocil:actions>
385091 ············<ocil:test_action_ref>ocil:ssg-encrypt_partitions_action:testaction:1</ocil:test_action_ref>385091 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>
385092 ··········</ocil:actions>385092 ··········</ocil:actions>
385093 ········</ocil:questionnaire>385093 ········</ocil:questionnaire>
385094 ········<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">385094 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
Max diff block lines reached; 3565659/3577468 bytes (99.67%) of diff not shown.
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
3.27 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
Ordering differences only
    
Offset 3, 11318 lines modifiedOffset 3, 11318 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwquality_system_auth_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·PAM·password·complexity·module·is·enabled·in·system-auth</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwquality_system_auth_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-zipl_enable_selinux_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-httpd_antivirus_scan_uploads_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·SELinux·Not·Disabled·in·zIPL</ocil:title>17 ······<ocil:title>Scan·All·Uploaded·Content·for·Malicious·Software</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-zipl_enable_selinux_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-httpd_antivirus_scan_uploads_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sebool_deny_ptrace_ocil:questionnaire:1">
23 ······<ocil:title>Set·the·GNOME3·Login·Warning·Banner·Text</ocil:title>23 ······<ocil:title>Disable·the·deny_ptrace·SELinux·Boolean</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sebool_deny_ptrace_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1">
29 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>29 ······<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·auditd·Rules·For·Unauthorized·Attempts·To·open·Are·Ordered·Correctly</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sebool_cups_execmem_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·the·cups_execmem·SELinux·Boolean</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sebool_cups_execmem_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_on_data_corruption_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_disable_autorun_ocil:questionnaire:1">
41 ······<ocil:title>Trigger·a·kernel·BUG·when·data·corruption·is·detected</ocil:title>41 ······<ocil:title>Disable·GNOME3·Automount·running</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_on_data_corruption_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_autorun_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-service_abrtd_disabled_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Automatic·Bug·Reporting·Tool·(abrtd)</ocil:title>47 ······<ocil:title>Enable·Public·Key·Authentication</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-service_abrtd_disabled_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_restorecon_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">
53 ······<ocil:title>Record·Any·Attempts·to·Run·restorecon</ocil:title>53 ······<ocil:title>Record·Attempts·to·perform·maintenance·activities</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_restorecon_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_grpquota_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_tmp_ocil:questionnaire:1">
59 ······<ocil:title>Add·grpquota·Option·to·/home</ocil:title>59 ······<ocil:title>Ensure·/var/tmp·Located·On·Separate·Partition</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_grpquota_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_tmp_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-encrypt_partitions_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">
65 ······<ocil:title>Encrypt·Partitions</ocil:title>65 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-encrypt_partitions_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>71 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_pt_chown_ocil:questionnaire:1"> 
77 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·pt_chown</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">
 77 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pt_chown_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>83 ······<ocil:title>Disable·Access·to·Network·bpf()·Syscall·From·Unprivileged·Processes</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-journald_forward_to_syslog_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sebool_deny_execmem_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·journald·is·configured·to·send·logs·to·rsyslog</ocil:title>89 ······<ocil:title>Configure·the·deny_execmem·SELinux·Boolean</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-journald_forward_to_syslog_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sebool_deny_execmem_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_defined_ocil:questionnaire:1"> 
95 ······<ocil:title>All·Interactive·Users·Must·Have·A·Home·Directory·Defined</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_ocil:questionnaire:1">
 95 ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·fchown</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_defined_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-httpd_require_client_certs_ocil:questionnaire:1">
101 ······<ocil:title>Uninstall·bind·Package</ocil:title>101 ······<ocil:title>Require·Client·Certificates</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-httpd_require_client_certs_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_gcc_plugin_structleak_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
107 ······<ocil:title>Force·initialization·of·variables·containing·userspace·addresses</ocil:title>107 ······<ocil:title>Ensure·that·/etc/cron.allow·exists</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_structleak_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_remote_access_encryption_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-no_nis_in_nsswitch_ocil:questionnaire:1">
113 ······<ocil:title>Require·Encryption·for·Remote·Access·in·GNOME3</ocil:title>113 ······<ocil:title>Name·Service·Switch·does·not·use·NIS</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_remote_access_encryption_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-no_nis_in_nsswitch_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-cups_disable_browsing_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
119 ······<ocil:title>Disable·Printer·Browsing·Entirely·if·Possible</ocil:title>119 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-cups_disable_browsing_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_net_cis_ocil:questionnaire:1"> 
125 ······<ocil:title>Ensure·Remote·Login·Warning·Banner·Is·Configured·Properly</ocil:title>124 ····<ocil:questionnaire·id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1">
Max diff block lines reached; 3416963/3429690 bytes (99.63%) of diff not shown.
3.26 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
3.26 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhel9-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhel9-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:9">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·9</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml">oval:ssg-installed_OS_is_rhel9:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHEL-9"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·9.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 379, 23 lines modifiedOffset 379, 23 lines modified
379 ··········</cpe-lang:logical-test>379 ··········</cpe-lang:logical-test>
380 ········</cpe-lang:platform>380 ········</cpe-lang:platform>
381 ········<cpe-lang:platform·id="package_bash">381 ········<cpe-lang:platform·id="package_bash">
382 ··········<cpe-lang:logical-test·operator="AND"·negate="false">382 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
383 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>383 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
384 ··········</cpe-lang:logical-test>384 ··········</cpe-lang:logical-test>
385 ········</cpe-lang:platform>385 ········</cpe-lang:platform>
386 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">386 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
387 ··········<cpe-lang:logical-test·operator="AND"·negate="false">387 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
388 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>388 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
389 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
390 ··········</cpe-lang:logical-test>389 ··········</cpe-lang:logical-test>
391 ········</cpe-lang:platform>390 ········</cpe-lang:platform>
392 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">391 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
393 ··········<cpe-lang:logical-test·operator="AND"·negate="false">392 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
394 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>393 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 394 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
395 ··········</cpe-lang:logical-test>395 ··········</cpe-lang:logical-test>
396 ········</cpe-lang:platform>396 ········</cpe-lang:platform>
397 ········<cpe-lang:platform·id="not_s390x_arch">397 ········<cpe-lang:platform·id="not_s390x_arch">
398 ··········<cpe-lang:logical-test·operator="AND"·negate="false">398 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
399 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>399 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
400 ··········</cpe-lang:logical-test>400 ··········</cpe-lang:logical-test>
401 ········</cpe-lang:platform>401 ········</cpe-lang:platform>
Offset 310419, 15 lines modifiedOffset 310419, 15 lines modified
310419 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>310419 ··············<xccdf-1.2:check-content-ref·href="ssg-rhel9-ocil.xml"·name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
310420 ············</xccdf-1.2:check>310420 ············</xccdf-1.2:check>
310421 ··········</xccdf-1.2:Rule>310421 ··········</xccdf-1.2:Rule>
310422 ········</xccdf-1.2:Group>310422 ········</xccdf-1.2:Group>
310423 ······</xccdf-1.2:Group>310423 ······</xccdf-1.2:Group>
310424 ····</xccdf-1.2:Benchmark>310424 ····</xccdf-1.2:Benchmark>
310425 ··</ds:component>310425 ··</ds:component>
310426 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-02-28T20:08:00">310426 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-oval.xml"·timestamp="2025-03-01T22:08:00">
310427 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">310427 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
310428 ······<oval-def:generator>310428 ······<oval-def:generator>
310429 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>310429 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
310430 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>310430 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
310431 ········<oval:schema_version>5.11</oval:schema_version>310431 ········<oval:schema_version>5.11</oval:schema_version>
310432 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>310432 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
310433 ······</oval-def:generator>310433 ······</oval-def:generator>
Offset 377198, 22912 lines modifiedOffset 377198, 22125 lines modified
377198 ············</oval-def:arithmetic>377198 ············</oval-def:arithmetic>
377199 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>377199 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
377200 ··········</oval-def:arithmetic>377200 ··········</oval-def:arithmetic>
377201 ········</oval-def:local_variable>377201 ········</oval-def:local_variable>
377202 ······</oval-def:variables>377202 ······</oval-def:variables>
377203 ····</oval-def:oval_definitions>377203 ····</oval-def:oval_definitions>
377204 ··</ds:component>377204 ··</ds:component>
377205 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-02-28T20:08:00">377205 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhel9-ocil.xml"·timestamp="2025-03-01T22:08:00">
377206 ····<ocil:ocil>377206 ····<ocil:ocil>
377207 ······<ocil:generator>377207 ······<ocil:generator>
377208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>377208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
377209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>377209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
377210 ········<ocil:schema_version>2.0</ocil:schema_version>377210 ········<ocil:schema_version>2.0</ocil:schema_version>
377211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>377211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
377212 ······</ocil:generator>377212 ······</ocil:generator>
377213 ······<ocil:questionnaires>377213 ······<ocil:questionnaires>
377214 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1"> 
377215 ··········<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title> 
377216 ··········<ocil:actions> 
377217 ············<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref> 
377218 ··········</ocil:actions> 
377219 ········</ocil:questionnaire> 
377220 ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> 
377221 ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title> 
377222 ··········<ocil:actions> 
377223 ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref> 
377224 ··········</ocil:actions> 
377225 ········</ocil:questionnaire> 
377226 ········<ocil:questionnaire·id="ocil:ssg-accounts_have_homedir_login_defs_ocil:questionnaire:1"> 
377227 ··········<ocil:title>Ensure·Home·Directories·are·Created·for·New·Users</ocil:title> 
377228 ··········<ocil:actions> 
377229 ············<ocil:test_action_ref>ocil:ssg-accounts_have_homedir_login_defs_action:testaction:1</ocil:test_action_ref> 
377230 ··········</ocil:actions> 
377231 ········</ocil:questionnaire> 
377232 ········<ocil:questionnaire·id="ocil:ssg-zipl_bootmap_is_up_to_date_ocil:questionnaire:1">377214 ········<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1">
377233 ··········<ocil:title>Ensure·zIPL·bootmap·is·up·to·date</ocil:title>377215 ··········<ocil:title>Prevent·remote·hosts·from·connecting·to·the·proxy·display</ocil:title>
377234 ··········<ocil:actions>377216 ··········<ocil:actions>
377235 ············<ocil:test_action_ref>ocil:ssg-zipl_bootmap_is_up_to_date_action:testaction:1</ocil:test_action_ref>377217 ············<ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref>
377236 ··········</ocil:actions>377218 ··········</ocil:actions>
377237 ········</ocil:questionnaire>377219 ········</ocil:questionnaire>
377238 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">377220 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
377239 ··········<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>377221 ··········<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
377240 ··········<ocil:actions>377222 ··········<ocil:actions>
377241 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>377223 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
377242 ··········</ocil:actions>377224 ··········</ocil:actions>
377243 ········</ocil:questionnaire>377225 ········</ocil:questionnaire>
377244 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1">377226 ········<ocil:questionnaire·id="ocil:ssg-package_samba-common_installed_ocil:questionnaire:1">
377245 ··········<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>377227 ··········<ocil:title>Install·the·Samba·Common·Package</ocil:title>
377246 ··········<ocil:actions>377228 ··········<ocil:actions>
377247 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>377229 ············<ocil:test_action_ref>ocil:ssg-package_samba-common_installed_action:testaction:1</ocil:test_action_ref>
377248 ··········</ocil:actions>377230 ··········</ocil:actions>
377249 ········</ocil:questionnaire>377231 ········</ocil:questionnaire>
377250 ········<ocil:questionnaire·id="ocil:ssg-audit_owner_change_failed_ppc64le_ocil:questionnaire:1">377232 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
377251 ··········<ocil:title>Configure·auditing·of·unsuccessful·ownership·changes·(ppc64le)</ocil:title>377233 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
377252 ··········<ocil:actions>377234 ··········<ocil:actions>
377253 ············<ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_ppc64le_action:testaction:1</ocil:test_action_ref>377235 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
377254 ··········</ocil:actions>377236 ··········</ocil:actions>
377255 ········</ocil:questionnaire>377237 ········</ocil:questionnaire>
377256 ········<ocil:questionnaire·id="ocil:ssg-package_opensc_installed_ocil:questionnaire:1"> 
377257 ··········<ocil:title>Install·the·opensc·Package·For·Multifactor·Authentication</ocil:title>377238 ········<ocil:questionnaire·id="ocil:ssg-sebool_cluster_can_network_connect_ocil:questionnaire:1">
 377239 ··········<ocil:title>Disable·the·cluster_can_network_connect·SELinux·Boolean</ocil:title>
377258 ··········<ocil:actions>377240 ··········<ocil:actions>
Max diff block lines reached; 3403717/3414978 bytes (99.67%) of diff not shown.
3.12 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
3.12 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
Ordering differences only
    
Offset 3, 22903 lines modifiedOffset 3, 22116 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1"> 
11 ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·chown</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"> 
17 ······<ocil:title>Uninstall·rsh-server·Package</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-accounts_have_homedir_login_defs_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·Home·Directories·are·Created·for·New·Users</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-accounts_have_homedir_login_defs_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-zipl_bootmap_is_up_to_date_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·zIPL·bootmap·is·up·to·date</ocil:title>11 ······<ocil:title>Prevent·remote·hosts·from·connecting·to·the·proxy·display</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-zipl_bootmap_is_up_to_date_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>17 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1"> 
41 ······<ocil:title>Restrict·Access·to·Kernel·Message·Buffer</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-package_samba-common_installed_ocil:questionnaire:1">
 23 ······<ocil:title>Install·the·Samba·Common·Package</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_samba-common_installed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_owner_change_failed_ppc64le_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
47 ······<ocil:title>Configure·auditing·of·unsuccessful·ownership·changes·(ppc64le)</ocil:title>29 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_ppc64le_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-package_opensc_installed_ocil:questionnaire:1"> 
53 ······<ocil:title>Install·the·opensc·Package·For·Multifactor·Authentication</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sebool_cluster_can_network_connect_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·the·cluster_can_network_connect·SELinux·Boolean</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-package_opensc_installed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sebool_cluster_can_network_connect_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_refcount_full_ocil:questionnaire:1">
59 ······<ocil:title>Verify·Owner·on·cron.d</ocil:title>41 ······<ocil:title>Perform·full·reference·count·validation</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_refcount_full_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sebool_irc_use_any_tcp_ports_ocil:questionnaire:1">
65 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>47 ······<ocil:title>Disable·the·irc_use_any_tcp_ports·SELinux·Boolean</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sebool_irc_use_any_tcp_ports_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_group_for_su_ocil:questionnaire:1">
71 ······<ocil:title>Install·fapolicyd·Package</ocil:title>53 ······<ocil:title>Enforce·Usage·of·pam_wheel·with·Group·Parameter·for·su·Authentication</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-use_pam_wheel_group_for_su_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_ocil:questionnaire:1"> 
77 ······<ocil:title>Set·Kernel·Parameter·to·Increase·Local·Port·Range</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_ocil:questionnaire:1">
 59 ······<ocil:title>Record·Unsuccessful·Ownership·Changes·to·Files·-·fchownat</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_local_port_range_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
83 ······<ocil:title>Enable·PAM</ocil:title>65 ······<ocil:title>Uninstall·vsftpd·Package</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User</ocil:title>71 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_use_openstack_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_ipsec_secrets_ocil:questionnaire:1">
95 ······<ocil:title>Disable·the·httpd_use_openstack·SELinux·Boolean</ocil:title>77 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.secrets·File</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_use_openstack_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sebool_tftp_anon_write_ocil:questionnaire:1">
101 ······<ocil:title>Disable·graphical·user·interface</ocil:title>83 ······<ocil:title>Disable·the·tftp_anon_write·SELinux·Boolean</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sebool_tftp_anon_write_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-package_tmux_installed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sebool_glance_use_fusefs_ocil:questionnaire:1">
107 ······<ocil:title>Install·the·tmux·Package</ocil:title>89 ······<ocil:title>Disable·the·glance_use_fusefs·SELinux·Boolean</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-package_tmux_installed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sebool_glance_use_fusefs_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1"> 
113 ······<ocil:title>Record·Any·Attempts·to·Run·semanage</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sebool_httpd_can_connect_ldap_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·the·httpd_can_connect_ldap·SELinux·Boolean</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sebool_httpd_can_connect_ldap_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-package_dhcp_removed_ocil:questionnaire:1"> 
119 ······<ocil:title>Uninstall·DHCP·Server·Package</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-sebool_squid_connect_any_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·the·squid_connect_any·SELinux·Boolean</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-package_dhcp_removed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sebool_squid_connect_any_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
123 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sysctl_user_max_user_namespaces_ocil:questionnaire:1"> 
Max diff block lines reached; 3260934/3272773 bytes (99.64%) of diff not shown.
2.49 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
2.39 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
Ordering differences only
    
Offset 346, 23 lines modifiedOffset 346, 23 lines modified
346 ······</cpe-lang:logical-test>346 ······</cpe-lang:logical-test>
347 ····</cpe-lang:platform>347 ····</cpe-lang:platform>
348 ····<cpe-lang:platform·id="package_bash">348 ····<cpe-lang:platform·id="package_bash">
349 ······<cpe-lang:logical-test·operator="AND"·negate="false">349 ······<cpe-lang:logical-test·operator="AND"·negate="false">
350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>350 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
351 ······</cpe-lang:logical-test>351 ······</cpe-lang:logical-test>
352 ····</cpe-lang:platform>352 ····</cpe-lang:platform>
353 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">353 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
354 ······<cpe-lang:logical-test·operator="AND"·negate="false">354 ······<cpe-lang:logical-test·operator="AND"·negate="false">
355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>355 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
356 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
357 ······</cpe-lang:logical-test>356 ······</cpe-lang:logical-test>
358 ····</cpe-lang:platform>357 ····</cpe-lang:platform>
359 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">358 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
360 ······<cpe-lang:logical-test·operator="AND"·negate="false">359 ······<cpe-lang:logical-test·operator="AND"·negate="false">
361 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>360 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 361 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
362 ······</cpe-lang:logical-test>362 ······</cpe-lang:logical-test>
363 ····</cpe-lang:platform>363 ····</cpe-lang:platform>
364 ····<cpe-lang:platform·id="not_s390x_arch">364 ····<cpe-lang:platform·id="not_s390x_arch">
365 ······<cpe-lang:logical-test·operator="AND"·negate="false">365 ······<cpe-lang:logical-test·operator="AND"·negate="false">
366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>366 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhel9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
367 ······</cpe-lang:logical-test>367 ······</cpe-lang:logical-test>
368 ····</cpe-lang:platform>368 ····</cpe-lang:platform>
1.57 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
1.57 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
    
Offset 19, 27 lines modifiedOffset 19, 27 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhv4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhv4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:enterprise_virtualization_manager:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Manager</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_app_is_rhv4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">32 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux:8::hypervisor">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Virtualization·4·Host</cpe-dict:title>
34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>34 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml">oval:ssg-installed_OS_is_rhv4:def:1</cpe-dict:check>
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ····</cpe-dict:cpe-list>36 ····</cpe-dict:cpe-list>
37 ··</ds:component>37 ··</ds:component>
38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-02-28T20:08:00">38 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-xccdf.xml"·timestamp="2025-03-01T22:08:00">
39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">39 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHV-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>40 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>41 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Virtualization·4</xccdf-1.2:title>
42 ······<xccdf-1.2:description>42 ······<xccdf-1.2:description>
43 ········This·guide·presents·a·catalog·of·security-relevant43 ········This·guide·presents·a·catalog·of·security-relevant
44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of44 configuration·settings·for·Red·Hat·Virtualization·4.·It·is·a·rendering·of
45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)45 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 162832, 15 lines modifiedOffset 162832, 15 lines modified
162832 ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>162832 ··············<xccdf-1.2:check-content-ref·href="ssg-rhv4-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
162833 ············</xccdf-1.2:check>162833 ············</xccdf-1.2:check>
162834 ··········</xccdf-1.2:Rule>162834 ··········</xccdf-1.2:Rule>
162835 ········</xccdf-1.2:Group>162835 ········</xccdf-1.2:Group>
162836 ······</xccdf-1.2:Group>162836 ······</xccdf-1.2:Group>
162837 ····</xccdf-1.2:Benchmark>162837 ····</xccdf-1.2:Benchmark>
162838 ··</ds:component>162838 ··</ds:component>
162839 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-02-28T20:08:00">162839 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-oval.xml"·timestamp="2025-03-01T22:08:00">
162840 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">162840 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
162841 ······<oval-def:generator>162841 ······<oval-def:generator>
162842 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>162842 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
162843 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>162843 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
162844 ········<oval:schema_version>5.11</oval:schema_version>162844 ········<oval:schema_version>5.11</oval:schema_version>
162845 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>162845 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
162846 ······</oval-def:generator>162846 ······</oval-def:generator>
Offset 195359, 12763 lines modifiedOffset 195359, 12496 lines modified
195359 ············</oval-def:arithmetic>195359 ············</oval-def:arithmetic>
195360 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>195360 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
195361 ··········</oval-def:arithmetic>195361 ··········</oval-def:arithmetic>
195362 ········</oval-def:local_variable>195362 ········</oval-def:local_variable>
195363 ······</oval-def:variables>195363 ······</oval-def:variables>
195364 ····</oval-def:oval_definitions>195364 ····</oval-def:oval_definitions>
195365 ··</ds:component>195365 ··</ds:component>
195366 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-02-28T20:08:00">195366 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhv4-ocil.xml"·timestamp="2025-03-01T22:08:00">
195367 ····<ocil:ocil>195367 ····<ocil:ocil>
195368 ······<ocil:generator>195368 ······<ocil:generator>
195369 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>195369 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
195370 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>195370 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
195371 ········<ocil:schema_version>2.0</ocil:schema_version>195371 ········<ocil:schema_version>2.0</ocil:schema_version>
195372 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>195372 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
195373 ······</ocil:generator>195373 ······</ocil:generator>
195374 ······<ocil:questionnaires>195374 ······<ocil:questionnaires>
195375 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1">195375 ········<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">
 195376 ··········<ocil:title>Uninstall·rsh-server·Package</ocil:title>
195376 ··········<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title> 
195377 ··········<ocil:actions> 
195378 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref> 
195379 ··········</ocil:actions> 
195380 ········</ocil:questionnaire> 
195381 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
195382 ··········<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title> 
195383 ··········<ocil:actions> 
195384 ············<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref> 
195385 ··········</ocil:actions> 
195386 ········</ocil:questionnaire> 
195387 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1"> 
195388 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> 
195389 ··········<ocil:actions>195377 ··········<ocil:actions>
195390 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>195378 ············<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>
195391 ··········</ocil:actions>195379 ··········</ocil:actions>
195392 ········</ocil:questionnaire>195380 ········</ocil:questionnaire>
195393 ········<ocil:questionnaire·id="ocil:ssg-package_tmux_installed_ocil:questionnaire:1">195381 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
195394 ··········<ocil:title>Install·the·tmux·Package</ocil:title>195382 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
195395 ··········<ocil:actions>195383 ··········<ocil:actions>
195396 ············<ocil:test_action_ref>ocil:ssg-package_tmux_installed_action:testaction:1</ocil:test_action_ref>195384 ············<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
195397 ··········</ocil:actions>195385 ··········</ocil:actions>
195398 ········</ocil:questionnaire>195386 ········</ocil:questionnaire>
195399 ········<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_share_music_ocil:questionnaire:1">195387 ········<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
195400 ··········<ocil:title>Disable·the·selinuxuser_share_music·SELinux·Boolean</ocil:title>195388 ··········<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>
195401 ··········<ocil:actions>195389 ··········<ocil:actions>
195402 ············<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_share_music_action:testaction:1</ocil:test_action_ref>195390 ············<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>
195403 ··········</ocil:actions>195391 ··········</ocil:actions>
195404 ········</ocil:questionnaire>195392 ········</ocil:questionnaire>
195405 ········<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">195393 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">
195406 ··········<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>195394 ··········<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>
195407 ··········<ocil:actions>195395 ··········<ocil:actions>
195408 ············<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>195396 ············<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>
195409 ··········</ocil:actions>195397 ··········</ocil:actions>
195410 ········</ocil:questionnaire>195398 ········</ocil:questionnaire>
195411 ········<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_net_ocil:questionnaire:1">195399 ········<ocil:questionnaire·id="ocil:ssg-file_owner_efi_user_cfg_ocil:questionnaire:1">
195412 ··········<ocil:title>Modify·the·System·Login·Banner·for·Remote·Connections</ocil:title>195400 ··········<ocil:title>Verify·/boot/grub2/user.cfg·User·Ownership</ocil:title>
195413 ··········<ocil:actions>195401 ··········<ocil:actions>
195414 ············<ocil:test_action_ref>ocil:ssg-banner_etc_issue_net_action:testaction:1</ocil:test_action_ref>195402 ············<ocil:test_action_ref>ocil:ssg-file_owner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
195415 ··········</ocil:actions>195403 ··········</ocil:actions>
195416 ········</ocil:questionnaire>195404 ········</ocil:questionnaire>
195417 ········<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">195405 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
195418 ··········<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>195406 ··········<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
195419 ··········<ocil:actions>195407 ··········<ocil:actions>
195420 ············<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>195408 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
195421 ··········</ocil:actions>195409 ··········</ocil:actions>
195422 ········</ocil:questionnaire>195410 ········</ocil:questionnaire>
195423 ········<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">195411 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
195424 ··········<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>195412 ··········<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>
195425 ··········<ocil:actions>195413 ··········<ocil:actions>
195426 ············<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>195414 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
195427 ··········</ocil:actions>195415 ··········</ocil:actions>
195428 ········</ocil:questionnaire>195416 ········</ocil:questionnaire>
195429 ········<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">195417 ········<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
195430 ··········<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>195418 ··········<ocil:title>Kernel·panic·oops</ocil:title>
195431 ··········<ocil:actions>195419 ··········<ocil:actions>
195432 ············<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>195420 ············<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
195433 ··········</ocil:actions>195421 ··········</ocil:actions>
195434 ········</ocil:questionnaire>195422 ········</ocil:questionnaire>
195435 ········<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">195423 ········<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_specify_remote_server_ocil:questionnaire:1">
195436 ··········<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>195424 ··········<ocil:title>Specify·a·Remote·NTP·Server</ocil:title>
195437 ··········<ocil:actions>195425 ··········<ocil:actions>
195438 ············<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>195426 ············<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
195439 ··········</ocil:actions>195427 ··········</ocil:actions>
195440 ········</ocil:questionnaire>195428 ········</ocil:questionnaire>
Max diff block lines reached; 1634867/1646816 bytes (99.27%) of diff not shown.
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
Ordering differences only
    
Offset 3, 12754 lines modifiedOffset 3, 12487 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">
 11 ······<ocil:title>Uninstall·rsh-server·Package</ocil:title>
11 ······<ocil:title>Verify·Group·Who·Owns·/var/log/messages·File</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Successful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_tmux_installed_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
29 ······<ocil:title>Install·the·tmux·Package</ocil:title>17 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_tmux_installed_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_share_music_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
35 ······<ocil:title>Disable·the·selinuxuser_share_music·SELinux·Boolean</ocil:title>23 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_share_music_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1"> 
41 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_net_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_efi_user_cfg_ocil:questionnaire:1">
47 ······<ocil:title>Modify·the·System·Login·Banner·for·Remote·Connections</ocil:title>35 ······<ocil:title>Verify·/boot/grub2/user.cfg·User·Ownership</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_net_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>47 ······<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
65 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>53 ······<ocil:title>Kernel·panic·oops</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_specify_remote_server_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·/var/log·Located·On·Separate·Partition</ocil:title>59 ······<ocil:title>Specify·a·Remote·NTP·Server</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1"> 
77 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_selinux_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·SELinux·Not·Disabled·in·/etc/default/grub</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_selinux_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1"> 
83 ······<ocil:title>Add·noexec·Option·to·Removable·Media·Partitions</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1">
 71 ······<ocil:title>Set·Password·Maximum·Consecutive·Repeating·Characters</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-mount_option_noexec_removable_partitions_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxrepeat_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
89 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_disk_full_action_ocil:questionnaire:1">
 77 ······<ocil:title>Configure·audispd's·Plugin·disk_full_action·When·Disk·Is·Full</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_disk_full_action_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchmod_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1">
95 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fchmod</ocil:title>83 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fchmodat</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmod_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>95 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1">
113 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>101 ······<ocil:title>Record·Any·Attempts·to·Run·semanage</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1"> 
119 ······<ocil:title>Enable·poison·without·sanity·check</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·the·selinuxuser_use_ssh_chroot·SELinux·Boolean</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_use_ssh_chroot_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1562272/1574443 bytes (99.23%) of diff not shown.
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle12-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle12-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.12-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.12-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:12">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·12</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:12">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·12</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml">oval:ssg-installed_OS_is_sle12:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-12"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·12.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 329, 23 lines modifiedOffset 329, 23 lines modified
329 ··········</cpe-lang:logical-test>329 ··········</cpe-lang:logical-test>
330 ········</cpe-lang:platform>330 ········</cpe-lang:platform>
331 ········<cpe-lang:platform·id="package_bash">331 ········<cpe-lang:platform·id="package_bash">
332 ··········<cpe-lang:logical-test·operator="AND"·negate="false">332 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
333 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>333 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
334 ··········</cpe-lang:logical-test>334 ··········</cpe-lang:logical-test>
335 ········</cpe-lang:platform>335 ········</cpe-lang:platform>
336 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">336 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
337 ··········<cpe-lang:logical-test·operator="AND"·negate="false">337 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
338 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>338 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
339 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
340 ··········</cpe-lang:logical-test>339 ··········</cpe-lang:logical-test>
341 ········</cpe-lang:platform>340 ········</cpe-lang:platform>
342 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">341 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
343 ··········<cpe-lang:logical-test·operator="AND"·negate="false">342 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
344 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>343 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 344 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
345 ··········</cpe-lang:logical-test>345 ··········</cpe-lang:logical-test>
346 ········</cpe-lang:platform>346 ········</cpe-lang:platform>
347 ········<cpe-lang:platform·id="not_s390x_arch">347 ········<cpe-lang:platform·id="not_s390x_arch">
348 ··········<cpe-lang:logical-test·operator="AND"·negate="false">348 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
349 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>349 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
350 ··········</cpe-lang:logical-test>350 ··········</cpe-lang:logical-test>
351 ········</cpe-lang:platform>351 ········</cpe-lang:platform>
Offset 186684, 15 lines modifiedOffset 186684, 15 lines modified
186684 ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>186684 ··············<xccdf-1.2:check-content-ref·href="ssg-sle12-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
186685 ············</xccdf-1.2:check>186685 ············</xccdf-1.2:check>
186686 ··········</xccdf-1.2:Rule>186686 ··········</xccdf-1.2:Rule>
186687 ········</xccdf-1.2:Group>186687 ········</xccdf-1.2:Group>
186688 ······</xccdf-1.2:Group>186688 ······</xccdf-1.2:Group>
186689 ····</xccdf-1.2:Benchmark>186689 ····</xccdf-1.2:Benchmark>
186690 ··</ds:component>186690 ··</ds:component>
186691 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-02-28T20:08:00">186691 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-oval.xml"·timestamp="2025-03-01T22:08:00">
186692 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">186692 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
186693 ······<oval-def:generator>186693 ······<oval-def:generator>
186694 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>186694 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
186695 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>186695 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
186696 ········<oval:schema_version>5.11</oval:schema_version>186696 ········<oval:schema_version>5.11</oval:schema_version>
186697 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>186697 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
186698 ······</oval-def:generator>186698 ······</oval-def:generator>
Offset 227001, 7001 lines modifiedOffset 227001, 7001 lines modified
227001 ············</oval-def:arithmetic>227001 ············</oval-def:arithmetic>
227002 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>227002 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
227003 ··········</oval-def:arithmetic>227003 ··········</oval-def:arithmetic>
227004 ········</oval-def:local_variable>227004 ········</oval-def:local_variable>
227005 ······</oval-def:variables>227005 ······</oval-def:variables>
227006 ····</oval-def:oval_definitions>227006 ····</oval-def:oval_definitions>
227007 ··</ds:component>227007 ··</ds:component>
227008 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-02-28T20:08:00">227008 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle12-ocil.xml"·timestamp="2025-03-01T22:08:00">
227009 ····<ocil:ocil>227009 ····<ocil:ocil>
227010 ······<ocil:generator>227010 ······<ocil:generator>
227011 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>227011 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
227012 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>227012 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
227013 ········<ocil:schema_version>2.0</ocil:schema_version>227013 ········<ocil:schema_version>2.0</ocil:schema_version>
227014 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>227014 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
227015 ······</ocil:generator>227015 ······</ocil:generator>
227016 ······<ocil:questionnaires>227016 ······<ocil:questionnaires>
227017 ········<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1"> 
227018 ··········<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>227017 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1">
 227018 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_chkpwd</ocil:title>
227019 ··········<ocil:actions>227019 ··········<ocil:actions>
227020 ············<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>227020 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>
227021 ··········</ocil:actions>227021 ··········</ocil:actions>
227022 ········</ocil:questionnaire>227022 ········</ocil:questionnaire>
227023 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">227023 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">
227024 ··········<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>227024 ··········<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>
227025 ··········<ocil:actions>227025 ··········<ocil:actions>
227026 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>227026 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>
227027 ··········</ocil:actions>227027 ··········</ocil:actions>
227028 ········</ocil:questionnaire>227028 ········</ocil:questionnaire>
227029 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1"> 
227030 ··········<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>227029 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
 227030 ··········<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
227031 ··········<ocil:actions>227031 ··········<ocil:actions>
227032 ············<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>227032 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
227033 ··········</ocil:actions>227033 ··········</ocil:actions>
227034 ········</ocil:questionnaire>227034 ········</ocil:questionnaire>
227035 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_ipsec_conf_ocil:questionnaire:1">227035 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
227036 ··········<ocil:title>Verify·User·Who·Owns·/etc/ipsec.conf·File</ocil:title>227036 ··········<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
227037 ··········<ocil:actions>227037 ··········<ocil:actions>
227038 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>227038 ············<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
227039 ··········</ocil:actions>227039 ··········</ocil:actions>
227040 ········</ocil:questionnaire>227040 ········</ocil:questionnaire>
227041 ········<ocil:questionnaire·id="ocil:ssg-package_cups_removed_ocil:questionnaire:1"> 
227042 ··········<ocil:title>Uninstall·CUPS·Package</ocil:title>227041 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
 227042 ··········<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
227043 ··········<ocil:actions>227043 ··········<ocil:actions>
227044 ············<ocil:test_action_ref>ocil:ssg-package_cups_removed_action:testaction:1</ocil:test_action_ref>227044 ············<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
227045 ··········</ocil:actions>227045 ··········</ocil:actions>
227046 ········</ocil:questionnaire>227046 ········</ocil:questionnaire>
227047 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_ipsec_secrets_ocil:questionnaire:1">227047 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
227048 ··········<ocil:title>Verify·Permissions·On·/etc/ipsec.secrets·File</ocil:title>227048 ··········<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>
227049 ··········<ocil:actions>227049 ··········<ocil:actions>
227050 ············<ocil:test_action_ref>ocil:ssg-file_permissions_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>227050 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
227051 ··········</ocil:actions>227051 ··········</ocil:actions>
227052 ········</ocil:questionnaire>227052 ········</ocil:questionnaire>
227053 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">227053 ········<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
227054 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>227054 ··········<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
227055 ··········<ocil:actions>227055 ··········<ocil:actions>
Max diff block lines reached; 1859641/1871760 bytes (99.35%) of diff not shown.
1.7 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
1.7 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
Ordering differences only
    
Offset 3, 6992 lines modifiedOffset 3, 6992 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1"> 
11 ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_chkpwd</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>17 ······<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_ipsec_conf_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
29 ······<ocil:title>Verify·User·Who·Owns·/etc/ipsec.conf·File</ocil:title>29 ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_cups_removed_ocil:questionnaire:1"> 
35 ······<ocil:title>Uninstall·CUPS·Package</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
 35 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_cups_removed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_ipsec_secrets_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Permissions·On·/etc/ipsec.secrets·File</ocil:title>41 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>47 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/gshadow</ocil:title>53 ······<ocil:title>Enable·cron·Service</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-enable_pam_namespace_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">
59 ······<ocil:title>Set·Up·a·Private·Namespace·in·PAM·Configuration</ocil:title>59 ······<ocil:title>Verify·/boot/grub2/grub.cfg·Group·Ownership</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-enable_pam_namespace_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>65 ······<ocil:title>Ensure·SMEP·is·not·disabled·during·boot</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1"> 
71 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_agent_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Any·Attempts·to·Run·ssh-agent</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_agent_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">
77 ······<ocil:title>Kernel·panic·oops</ocil:title>77 ······<ocil:title>Require·Authentication·for·Emergency·Systemd·Target</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chage_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chage</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chage_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_dhcp_client_removed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
89 ······<ocil:title>Uninstall·DHCP·Client·Package</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_dhcp_client_removed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
95 ······<ocil:title>Uninstall·Samba·Package</ocil:title>95 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-package_samba_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
101 ······<ocil:title>Set·Default·iptables·Policy·for·Incoming·Packets</ocil:title>101 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-is_fips_mode_enabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_lcredit_ocil:questionnaire:1">
107 ······<ocil:title>Verify·'/proc/sys/crypto/fips_enabled'·exists</ocil:title>107 ······<ocil:title>Set·Password·Strength·Minimum·Lowercase·Characters</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-is_fips_mode_enabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-cracklib_accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1"> 
113 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_selinux_ocil:questionnaire:1">
 113 ······<ocil:title>Verify·User·Who·Owns·/etc/selinux·Directory</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_selinux_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1"> 
119 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
 119 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 1774833/1787345 bytes (99.30%) of diff not shown.
2.49 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
2.39 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
Ordering differences only
    
Offset 290, 23 lines modifiedOffset 290, 23 lines modified
290 ······</cpe-lang:logical-test>290 ······</cpe-lang:logical-test>
291 ····</cpe-lang:platform>291 ····</cpe-lang:platform>
292 ····<cpe-lang:platform·id="package_bash">292 ····<cpe-lang:platform·id="package_bash">
293 ······<cpe-lang:logical-test·operator="AND"·negate="false">293 ······<cpe-lang:logical-test·operator="AND"·negate="false">
294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>294 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
295 ······</cpe-lang:logical-test>295 ······</cpe-lang:logical-test>
296 ····</cpe-lang:platform>296 ····</cpe-lang:platform>
297 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">297 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
298 ······<cpe-lang:logical-test·operator="AND"·negate="false">298 ······<cpe-lang:logical-test·operator="AND"·negate="false">
299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>299 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
300 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
301 ······</cpe-lang:logical-test>300 ······</cpe-lang:logical-test>
302 ····</cpe-lang:platform>301 ····</cpe-lang:platform>
303 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">302 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
304 ······<cpe-lang:logical-test·operator="AND"·negate="false">303 ······<cpe-lang:logical-test·operator="AND"·negate="false">
305 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>304 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 305 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
306 ······</cpe-lang:logical-test>306 ······</cpe-lang:logical-test>
307 ····</cpe-lang:platform>307 ····</cpe-lang:platform>
308 ····<cpe-lang:platform·id="not_s390x_arch">308 ····<cpe-lang:platform·id="not_s390x_arch">
309 ······<cpe-lang:logical-test·operator="AND"·negate="false">309 ······<cpe-lang:logical-test·operator="AND"·negate="false">
310 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>310 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
311 ······</cpe-lang:logical-test>311 ······</cpe-lang:logical-test>
312 ····</cpe-lang:platform>312 ····</cpe-lang:platform>
1.88 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
1.88 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
    
Offset 21, 27 lines modifiedOffset 21, 27 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-sle15-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-sle15-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_desktop:15">
31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Desktop·15</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:linux_enterprise_server:15">
35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SUSE·Linux·Enterprise·Server·15</cpe-dict:title>
36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>36 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml">oval:ssg-installed_OS_is_sle15:def:1</cpe-dict:check>
37 ······</cpe-dict:cpe-item>37 ······</cpe-dict:cpe-item>
38 ····</cpe-dict:cpe-list>38 ····</cpe-dict:cpe-list>
39 ··</ds:component>39 ··</ds:component>
40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-02-28T20:08:00">40 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-xccdf.xml"·timestamp="2025-03-01T22:08:00">
41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">41 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLE-15"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>42 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>43 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·15</xccdf-1.2:title>
44 ······<xccdf-1.2:description>44 ······<xccdf-1.2:description>
45 ········This·guide·presents·a·catalog·of·security-relevant45 ········This·guide·presents·a·catalog·of·security-relevant
46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of46 configuration·settings·for·SUSE·Linux·Enterprise·15.·It·is·a·rendering·of
47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)47 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 363, 23 lines modifiedOffset 363, 23 lines modified
363 ··········</cpe-lang:logical-test>363 ··········</cpe-lang:logical-test>
364 ········</cpe-lang:platform>364 ········</cpe-lang:platform>
365 ········<cpe-lang:platform·id="package_bash">365 ········<cpe-lang:platform·id="package_bash">
366 ··········<cpe-lang:logical-test·operator="AND"·negate="false">366 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
367 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>367 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
368 ··········</cpe-lang:logical-test>368 ··········</cpe-lang:logical-test>
369 ········</cpe-lang:platform>369 ········</cpe-lang:platform>
370 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">370 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
371 ··········<cpe-lang:logical-test·operator="AND"·negate="false">371 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
372 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>372 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
373 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
374 ··········</cpe-lang:logical-test>373 ··········</cpe-lang:logical-test>
375 ········</cpe-lang:platform>374 ········</cpe-lang:platform>
376 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">375 ········<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
377 ··········<cpe-lang:logical-test·operator="AND"·negate="false">376 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
378 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>377 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 378 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
379 ··········</cpe-lang:logical-test>379 ··········</cpe-lang:logical-test>
380 ········</cpe-lang:platform>380 ········</cpe-lang:platform>
381 ········<cpe-lang:platform·id="not_s390x_arch">381 ········<cpe-lang:platform·id="not_s390x_arch">
382 ··········<cpe-lang:logical-test·operator="AND"·negate="false">382 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
383 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>383 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
384 ··········</cpe-lang:logical-test>384 ··········</cpe-lang:logical-test>
385 ········</cpe-lang:platform>385 ········</cpe-lang:platform>
Offset 200277, 15 lines modifiedOffset 200277, 15 lines modified
200277 ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>200277 ··············<xccdf-1.2:check-content-ref·href="ssg-sle15-ocil.xml"·name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
200278 ············</xccdf-1.2:check>200278 ············</xccdf-1.2:check>
200279 ··········</xccdf-1.2:Rule>200279 ··········</xccdf-1.2:Rule>
200280 ········</xccdf-1.2:Group>200280 ········</xccdf-1.2:Group>
200281 ······</xccdf-1.2:Group>200281 ······</xccdf-1.2:Group>
200282 ····</xccdf-1.2:Benchmark>200282 ····</xccdf-1.2:Benchmark>
200283 ··</ds:component>200283 ··</ds:component>
200284 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-02-28T20:08:00">200284 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-oval.xml"·timestamp="2025-03-01T22:08:00">
200285 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">200285 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
200286 ······<oval-def:generator>200286 ······<oval-def:generator>
200287 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>200287 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
200288 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>200288 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
200289 ········<oval:schema_version>5.11</oval:schema_version>200289 ········<oval:schema_version>5.11</oval:schema_version>
200290 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>200290 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
200291 ······</oval-def:generator>200291 ······</oval-def:generator>
Offset 242596, 11781 lines modifiedOffset 242596, 11781 lines modified
242596 ············</oval-def:arithmetic>242596 ············</oval-def:arithmetic>
242597 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>242597 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
242598 ··········</oval-def:arithmetic>242598 ··········</oval-def:arithmetic>
242599 ········</oval-def:local_variable>242599 ········</oval-def:local_variable>
242600 ······</oval-def:variables>242600 ······</oval-def:variables>
242601 ····</oval-def:oval_definitions>242601 ····</oval-def:oval_definitions>
242602 ··</ds:component>242602 ··</ds:component>
242603 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-02-28T20:08:00">242603 ··<ds:component·id="scap_org.open-scap_comp_ssg-sle15-ocil.xml"·timestamp="2025-03-01T22:08:00">
242604 ····<ocil:ocil>242604 ····<ocil:ocil>
242605 ······<ocil:generator>242605 ······<ocil:generator>
242606 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>242606 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
242607 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>242607 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
242608 ········<ocil:schema_version>2.0</ocil:schema_version>242608 ········<ocil:schema_version>2.0</ocil:schema_version>
242609 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>242609 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
242610 ······</ocil:generator>242610 ······</ocil:generator>
242611 ······<ocil:questionnaires>242611 ······<ocil:questionnaires>
242612 ········<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1">242612 ········<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">
242613 ··········<ocil:title>Use·Only·FIPS·140-2·Validated·Ciphers</ocil:title>242613 ··········<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>
242614 ··········<ocil:actions>242614 ··········<ocil:actions>
242615 ············<ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_ordered_stig_action:testaction:1</ocil:test_action_ref>242615 ············<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>
242616 ··········</ocil:actions>242616 ··········</ocil:actions>
242617 ········</ocil:questionnaire>242617 ········</ocil:questionnaire>
242618 ········<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">242618 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
242619 ··········<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>242619 ··········<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
242620 ··········<ocil:actions>242620 ··········<ocil:actions>
242621 ············<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>242621 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
242622 ··········</ocil:actions>242622 ··········</ocil:actions>
242623 ········</ocil:questionnaire>242623 ········</ocil:questionnaire>
242624 ········<ocil:questionnaire·id="ocil:ssg-harden_sshd_crypto_policy_ocil:questionnaire:1">242624 ········<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">
242625 ··········<ocil:title>Harden·SSHD·Crypto·Policy</ocil:title>242625 ··········<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>
242626 ··········<ocil:actions>242626 ··········<ocil:actions>
242627 ············<ocil:test_action_ref>ocil:ssg-harden_sshd_crypto_policy_action:testaction:1</ocil:test_action_ref>242627 ············<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>
242628 ··········</ocil:actions>242628 ··········</ocil:actions>
242629 ········</ocil:questionnaire>242629 ········</ocil:questionnaire>
242630 ········<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">242630 ········<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
242631 ··········<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>242631 ··········<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
242632 ··········<ocil:actions>242632 ··········<ocil:actions>
242633 ············<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>242633 ············<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
242634 ··········</ocil:actions>242634 ··········</ocil:actions>
242635 ········</ocil:questionnaire>242635 ········</ocil:questionnaire>
242636 ········<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">242636 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">
242637 ··········<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>242637 ··········<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>
242638 ··········<ocil:actions>242638 ··········<ocil:actions>
242639 ············<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>242639 ············<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>
242640 ··········</ocil:actions>242640 ··········</ocil:actions>
242641 ········</ocil:questionnaire>242641 ········</ocil:questionnaire>
242642 ········<ocil:questionnaire·id="ocil:ssg-file_owner_at_allow_ocil:questionnaire:1">242642 ········<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">
242643 ··········<ocil:title>Verify·User·Who·Owns·/etc/at.allow·file</ocil:title>242643 ··········<ocil:title>Configure·Backups·of·User·Data</ocil:title>
242644 ··········<ocil:actions>242644 ··········<ocil:actions>
242645 ············<ocil:test_action_ref>ocil:ssg-file_owner_at_allow_action:testaction:1</ocil:test_action_ref>242645 ············<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>
242646 ··········</ocil:actions>242646 ··········</ocil:actions>
242647 ········</ocil:questionnaire>242647 ········</ocil:questionnaire>
242648 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">242648 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1">
242649 ··········<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>242649 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·crontab</ocil:title>
242650 ··········<ocil:actions>242650 ··········<ocil:actions>
242651 ············<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>242651 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1</ocil:test_action_ref>
242652 ··········</ocil:actions>242652 ··········</ocil:actions>
242653 ········</ocil:questionnaire>242653 ········</ocil:questionnaire>
Max diff block lines reached; 1961417/1973747 bytes (99.38%) of diff not shown.
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
Ordering differences only
    
Offset 3, 11772 lines modifiedOffset 3, 11772 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_ciphers_ordered_stig_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-grub2_password_ocil:questionnaire:1">
11 ······<ocil:title>Use·Only·FIPS·140-2·Validated·Ciphers</ocil:title>11 ······<ocil:title>Set·Boot·Loader·Password·in·grub2</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_ordered_stig_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1"> 
17 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Ownership</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
 17 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-harden_sshd_crypto_policy_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">
23 ······<ocil:title>Harden·SSHD·Crypto·Policy</ocil:title>23 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-harden_sshd_crypto_policy_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
29 ······<ocil:title>Deactivate·Wireless·Network·Interfaces</ocil:title>29 ······<ocil:title>Verify·User·Who·Owns·Backup·gshadow·File</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-no_forward_files_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">
35 ······<ocil:title>Verify·No·.forward·Files·Exist</ocil:title>35 ······<ocil:title>Verify·Permissions·on·cron.monthly</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_at_allow_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">
41 ······<ocil:title>Verify·User·Who·Owns·/etc/at.allow·file</ocil:title>41 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_at_allow_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·crontab</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_weekly_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·Permissions·on·cron.weekly</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_weekly_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1">
59 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>59 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·su</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1"> 
65 ······<ocil:title>Uninstall·bind·Package</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_ocil:questionnaire:1">
 65 ······<ocil:title>Enable·GNOME3·Screensaver·Idle·Activation</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-apparmor_configured_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·AppArmor·is·Active·and·Configured</ocil:title>71 ······<ocil:title>Enable·the·NTP·Daemon</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-apparmor_configured_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_ntp_enabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_lock_enabled_ocil:questionnaire:1">
77 ······<ocil:title>Enable·module·signature·verification</ocil:title>77 ······<ocil:title>Enable·GNOME3·Screensaver·Lock·After·Idle·Period</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_lock_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1"> 
83 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv6·Interfaces</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1">
 83 ······<ocil:title>Disable·Avahi·Server·Software</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
89 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>89 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-dir_group_ownership_library_dirs_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Root·Group·Ownership</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-dir_group_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> 
101 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">
 101 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1"> 
107 ······<ocil:title>Add·nosuid·Option·to·/var/log</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-package_talk-server_removed_ocil:questionnaire:1">
 107 ······<ocil:title>Uninstall·talk-server·Package</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nosuid_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-package_talk-server_removed_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
113 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1">
 113 ······<ocil:title>Configure·AIDE·to·Verify·Extended·Attributes</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-aide_verify_ext_attributes_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_passwd_timeout_ocil:questionnaire:1">
119 ······<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title>119 ······<ocil:title>Ensure·sudo·passwd_timeout·is·appropriate·-·sudo·passwd_timeout</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sudo_add_passwd_timeout_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1873523/1885838 bytes (99.35%) of diff not shown.
2.49 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
2.39 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
Ordering differences only
    
Offset 324, 23 lines modifiedOffset 324, 23 lines modified
324 ······</cpe-lang:logical-test>324 ······</cpe-lang:logical-test>
325 ····</cpe-lang:platform>325 ····</cpe-lang:platform>
326 ····<cpe-lang:platform·id="package_bash">326 ····<cpe-lang:platform·id="package_bash">
327 ······<cpe-lang:logical-test·operator="AND"·negate="false">327 ······<cpe-lang:logical-test·operator="AND"·negate="false">
328 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>328 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
329 ······</cpe-lang:logical-test>329 ······</cpe-lang:logical-test>
330 ····</cpe-lang:platform>330 ····</cpe-lang:platform>
331 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">331 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">
332 ······<cpe-lang:logical-test·operator="AND"·negate="false">332 ······<cpe-lang:logical-test·operator="AND"·negate="false">
333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>333 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>
334 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/> 
335 ······</cpe-lang:logical-test>334 ······</cpe-lang:logical-test>
336 ····</cpe-lang:platform>335 ····</cpe-lang:platform>
337 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">336 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
338 ······<cpe-lang:logical-test·operator="AND"·negate="false">337 ······<cpe-lang:logical-test·operator="AND"·negate="false">
339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>338 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
 339 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
340 ······</cpe-lang:logical-test>340 ······</cpe-lang:logical-test>
341 ····</cpe-lang:platform>341 ····</cpe-lang:platform>
342 ····<cpe-lang:platform·id="not_s390x_arch">342 ····<cpe-lang:platform·id="not_s390x_arch">
343 ······<cpe-lang:logical-test·operator="AND"·negate="false">343 ······<cpe-lang:logical-test·operator="AND"·negate="false">
344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>344 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
345 ······</cpe-lang:logical-test>345 ······</cpe-lang:logical-test>
346 ····</cpe-lang:platform>346 ····</cpe-lang:platform>
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
    
Offset 21, 15 lines modifiedOffset 21, 15 lines modified
21 ····<ds:checks>21 ····<ds:checks>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>
24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>24 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>
25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>25 ······<ds:component-ref·id="scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.micro.5-patch.xml.bz2"·xlink:href="https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2"/>
26 ····</ds:checks>26 ····</ds:checks>
27 ··</ds:data-stream>27 ··</ds:data-stream>
28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">28 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">29 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">30 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">
31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>31 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>
32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>32 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
33 ······</cpe-dict:cpe-item>33 ······</cpe-dict:cpe-item>
34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">34 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">
35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>35 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 ······</cpe-dict:cpe-item>41 ······</cpe-dict:cpe-item>
42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">42 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">
43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>43 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>
44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>44 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
45 ······</cpe-dict:cpe-item>45 ······</cpe-dict:cpe-item>
46 ····</cpe-dict:cpe-list>46 ····</cpe-dict:cpe-list>
47 ··</ds:component>47 ··</ds:component>
48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-02-28T20:08:00">48 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2025-03-01T22:08:00">
49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">49 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>50 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>51 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>
52 ······<xccdf-1.2:description>52 ······<xccdf-1.2:description>
53 ········This·guide·presents·a·catalog·of·security-relevant53 ········This·guide·presents·a·catalog·of·security-relevant
54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of54 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of
55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)55 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 124816, 15 lines modifiedOffset 124816, 15 lines modified
124816 ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/>124816 ··············<xccdf-1.2:check-content-ref·href="ssg-slmicro5-ocil.xml"·name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/>
124817 ············</xccdf-1.2:check>124817 ············</xccdf-1.2:check>
124818 ··········</xccdf-1.2:Rule>124818 ··········</xccdf-1.2:Rule>
124819 ········</xccdf-1.2:Group>124819 ········</xccdf-1.2:Group>
124820 ······</xccdf-1.2:Group>124820 ······</xccdf-1.2:Group>
124821 ····</xccdf-1.2:Benchmark>124821 ····</xccdf-1.2:Benchmark>
124822 ··</ds:component>124822 ··</ds:component>
124823 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-02-28T20:08:00">124823 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-oval.xml"·timestamp="2025-03-01T22:08:00">
124824 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">124824 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
124825 ······<oval-def:generator>124825 ······<oval-def:generator>
124826 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>124826 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
124827 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>124827 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.5</oval:product_version>
124828 ········<oval:schema_version>5.11</oval:schema_version>124828 ········<oval:schema_version>5.11</oval:schema_version>
124829 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>124829 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
124830 ······</oval-def:generator>124830 ······</oval-def:generator>
Offset 146446, 3789 lines modifiedOffset 146446, 3789 lines modified
146446 ············</oval-def:arithmetic>146446 ············</oval-def:arithmetic>
146447 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>146447 ············<oval-def:variable_component·var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
146448 ··········</oval-def:arithmetic>146448 ··········</oval-def:arithmetic>
146449 ········</oval-def:local_variable>146449 ········</oval-def:local_variable>
146450 ······</oval-def:variables>146450 ······</oval-def:variables>
146451 ····</oval-def:oval_definitions>146451 ····</oval-def:oval_definitions>
146452 ··</ds:component>146452 ··</ds:component>
146453 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-02-28T20:08:00">146453 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"·timestamp="2025-03-01T22:08:00">
146454 ····<ocil:ocil>146454 ····<ocil:ocil>
146455 ······<ocil:generator>146455 ······<ocil:generator>
146456 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>146456 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
146457 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>146457 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
146458 ········<ocil:schema_version>2.0</ocil:schema_version>146458 ········<ocil:schema_version>2.0</ocil:schema_version>
146459 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>146459 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
146460 ······</ocil:generator>146460 ······</ocil:generator>
146461 ······<ocil:questionnaires>146461 ······<ocil:questionnaires>
146462 ········<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">146462 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1">
146463 ··········<ocil:title>Ensure·Software·Patches·Installed</ocil:title>146463 ··········<ocil:title>Record·Any·Attempts·to·Run·semanage</ocil:title>
146464 ··········<ocil:actions>146464 ··········<ocil:actions>
146465 ············<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>146465 ············<ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>
146466 ··········</ocil:actions>146466 ··········</ocil:actions>
146467 ········</ocil:questionnaire>146467 ········</ocil:questionnaire>
146468 ········<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">146468 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_lastlog_ocil:questionnaire:1">
146469 ··········<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>146469 ··········<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·lastlog</ocil:title>
146470 ··········<ocil:actions>146470 ··········<ocil:actions>
146471 ············<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>146471 ············<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_lastlog_action:testaction:1</ocil:test_action_ref>
146472 ··········</ocil:actions>146472 ··········</ocil:actions>
146473 ········</ocil:questionnaire>146473 ········</ocil:questionnaire>
146474 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
146475 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>146474 ········<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1">
 146475 ··········<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>
146476 ··········<ocil:actions>146476 ··········<ocil:actions>
146477 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>146477 ············<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>
146478 ··········</ocil:actions>146478 ··········</ocil:actions>
146479 ········</ocil:questionnaire>146479 ········</ocil:questionnaire>
146480 ········<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">146480 ········<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
146481 ··········<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>146481 ··········<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
146482 ··········<ocil:actions>146482 ··········<ocil:actions>
146483 ············<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>146483 ············<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
146484 ··········</ocil:actions>146484 ··········</ocil:actions>
146485 ········</ocil:questionnaire>146485 ········</ocil:questionnaire>
146486 ········<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">146486 ········<ocil:questionnaire·id="ocil:ssg-selinux_user_login_roles_ocil:questionnaire:1">
146487 ··········<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>146487 ··········<ocil:title>Map·System·Users·To·The·Appropriate·SELinux·Role</ocil:title>
146488 ··········<ocil:actions>146488 ··········<ocil:actions>
146489 ············<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>146489 ············<ocil:test_action_ref>ocil:ssg-selinux_user_login_roles_action:testaction:1</ocil:test_action_ref>
146490 ··········</ocil:actions>146490 ··········</ocil:actions>
146491 ········</ocil:questionnaire>146491 ········</ocil:questionnaire>
146492 ········<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">146492 ········<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">
146493 ··········<ocil:title>Limit·Users'·SSH·Access</ocil:title>146493 ··········<ocil:title>Disable·Dovecot·Service</ocil:title>
146494 ··········<ocil:actions>146494 ··········<ocil:actions>
146495 ············<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>146495 ············<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>
146496 ··········</ocil:actions>146496 ··········</ocil:actions>
146497 ········</ocil:questionnaire>146497 ········</ocil:questionnaire>
146498 ········<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">146498 ········<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
146499 ··········<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>146499 ··········<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
146500 ··········<ocil:actions>146500 ··········<ocil:actions>
146501 ············<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>146501 ············<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
146502 ··········</ocil:actions>146502 ··········</ocil:actions>
146503 ········</ocil:questionnaire>146503 ········</ocil:questionnaire>
146504 ········<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1"> 
146505 ··········<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>146504 ········<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
 146505 ··········<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>
146506 ··········<ocil:actions>146506 ··········<ocil:actions>
146507 ············<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>146507 ············<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
146508 ··········</ocil:actions>146508 ··········</ocil:actions>
146509 ········</ocil:questionnaire>146509 ········</ocil:questionnaire>
146510 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">146510 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1">
146511 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>146511 ··········<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title>
146512 ··········<ocil:actions>146512 ··········<ocil:actions>
146513 ············<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>146513 ············<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref>
146514 ··········</ocil:actions>146514 ··········</ocil:actions>
146515 ········</ocil:questionnaire>146515 ········</ocil:questionnaire>
146516 ········<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">146516 ········<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
146517 ··········<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>146517 ··········<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
146518 ··········<ocil:actions>146518 ··········<ocil:actions>
146519 ············<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>146519 ············<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
146520 ··········</ocil:actions>146520 ··········</ocil:actions>
146521 ········</ocil:questionnaire>146521 ········</ocil:questionnaire>
146522 ········<ocil:questionnaire·id="ocil:ssg-unnecessary_firewalld_services_ports_disabled_ocil:questionnaire:1"> 
Max diff block lines reached; 1041562/1053999 bytes (98.82%) of diff not shown.
983 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
983 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
Ordering differences only
    
Offset 3, 3780 lines modifiedOffset 3, 3780 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1">
11 ······<ocil:title>Ensure·Software·Patches·Installed</ocil:title>11 ······<ocil:title>Record·Any·Attempts·to·Run·semanage</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_lastlog_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>17 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·lastlog</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_lastlog_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1">
 23 ······<ocil:title>All·Interactive·Users·Home·Directories·Must·Exist</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
29 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>29 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-selinux_user_login_roles_ocil:questionnaire:1">
35 ······<ocil:title>Set·Default·iptables·Policy·for·Forwarded·Packets</ocil:title>35 ······<ocil:title>Map·System·Users·To·The·Appropriate·SELinux·Role</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-selinux_user_login_roles_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">
41 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>41 ······<ocil:title>Disable·Dovecot·Service</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
47 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>47 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1"> 
53 ······<ocil:title>Set·existing·passwords·a·period·of·inactivity·before·they·been·locked</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
 53 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1">
59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>59 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>65 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-unnecessary_firewalld_services_ports_disabled_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·Unnecessary·Services·and·Ports·Are·Not·Accepted</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_ocil:questionnaire:1">
 71 ······<ocil:title>Limit·Password·Reuse</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-unnecessary_firewalld_services_ports_disabled_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"> 
77 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Loading·-·init_module</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1">
 77 ······<ocil:title>Verify·that·system·commands·directories·have·root·ownership</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>83 ······<ocil:title>Set·Default·ip6tables·Policy·for·Incoming·Packets</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-install_smartcard_packages_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-account_temp_expire_date_ocil:questionnaire:1">
89 ······<ocil:title>Install·Smart·Card·Packages·For·Multifactor·Authentication</ocil:title>89 ······<ocil:title>Assign·Expiration·Date·to·Temporary·Accounts</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-install_smartcard_packages_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-account_temp_expire_date_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-set_nftables_table_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title>95 ······<ocil:title>Ensure·a·Table·Exists·for·Nftables</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1"> 
101 ······<ocil:title>Add·nodev·Option·to·Removable·Media·Partitions</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-mount_option_nodev_removable_partitions_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-permissions_local_audit_binaries_ocil:questionnaire:1"> 
107 ······<ocil:title>Verify·Permissions·of·Local·Logs·of·audit·Tools</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-ssh_private_keys_have_passcode_ocil:questionnaire:1">
 107 ······<ocil:title>OpenSSH·Service·Must·Use·Passcode·for·Their·Private·Keys</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-permissions_local_audit_binaries_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-ssh_private_keys_have_passcode_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1"> 
113 ······<ocil:title>Disable·DCCP·Support</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
 113 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_module_dccp_disabled_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-chronyd_configure_pool_and_server_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
119 ······<ocil:title>Chrony·Configure·Pool·and·Server</ocil:title>119 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-chronyd_configure_pool_and_server_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 993479/1006243 bytes (98.73%) of diff not shown.